CVE-2017-4951: CSRF
Published Jan 29, 2018
·Updated
VMware AirWatch Console (9.2.x before 9.2.2 and 9.1.x before 9.1.5) contains a Cross Site Request Forgery vulnerability when accessing the App Catalog. An attacker may exploit this issue by tricking users into installing a malicious application on their devices.
Affected Software
2 affected components
VMware AirWatch>=9.1<9.1.5
VMware AirWatch>=9.2<9.2.2
Remediation
Event History
Jan 29, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-4951?
CVE-2017-4951 has a medium severity rating due to its Cross Site Request Forgery vulnerability.
2
How do I fix CVE-2017-4951?
To fix CVE-2017-4951, update VMware AirWatch to version 9.2.2 or later, or 9.1.5 or later.
3
What products are affected by CVE-2017-4951?
CVE-2017-4951 affects VMware AirWatch versions prior to 9.2.2 and 9.1.5.
4
What type of vulnerability is CVE-2017-4951?
CVE-2017-4951 is classified as a Cross Site Request Forgery vulnerability.
5
What can an attacker do with CVE-2017-4951?
An attacker can exploit CVE-2017-4951 to trick users into installing malicious applications on their devices.