CVE-2018-6959: Critical severity VMware vRealize Automation vulnerability
Published Apr 13, 2018
·Updated
VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs. Exploitation of this issue may lead to the hijacking of a valid vRA user's session.
Affected Software
1 affected component
VMware vRealize Automation<7.4.0
Event History
Apr 13, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Data Sourced
via NVD·01:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2018-6959.
2
What is the title of this vulnerability?
The title of this vulnerability is VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs.
3
What is the severity of CVE-2018-6959?
The severity of CVE-2018-6959 is critical with a CVSS score of 9.8.
4
What software versions are affected by CVE-2018-6959?
VMware vRealize Automation versions prior to 7.4.0 are affected by CVE-2018-6959.
5
How can this vulnerability be exploited?
Exploitation of this vulnerability may lead to the hijacking of a valid vRA user's session.