CVE-2017-4947: Critical severity vmware vrealize automation vulnerability
VMware vRealize Automation (7.3 and 7.2) and vSphere Integrated Containers (1.x before 1.3) contain a deserialization vulnerability via Xenon. Successful exploitation of this issue may allow remote attackers to execute arbitrary code on the appliance.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-4947?
CVE-2017-4947 is a deserialization vulnerability found in VMware vRealize Automation (7.3 and 7.2) and vSphere Integrated Containers (1.x before 1.3) via Xenon, which allows remote attackers to execute arbitrary code.
How severe is CVE-2017-4947?
CVE-2017-4947 has a severity rating of 9.8 (Critical).
How can CVE-2017-4947 be exploited?
CVE-2017-4947 can be exploited remotely by attackers.
Which software versions are affected by CVE-2017-4947?
VMware vRealize Automation 7.2.0, 7.3.0, and vSphere Integrated Containers up to version 1.3.0 are affected by CVE-2017-4947.
Are there any resources for more information about CVE-2017-4947?
Yes, you can find more information about CVE-2017-4947 at the following references: [1] (http://www.securityfocus.com/bid/102852), [2] (http://www.securitytracker.com/id/1040289), [3] (http://www.securitytracker.com/id/1040290).