First published: Tue Nov 13 2018(Updated: )
VMware vRealize Log Insight (4.7.x before 4.7.1 and 4.6.x before 4.6.2) contains a vulnerability due to improper authorization in the user registration method. Successful exploitation of this issue may allow Admin users with view only permission to perform certain administrative functions which they are not allowed to perform.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vRealize Log Insight | >=4.6<4.6.2 | |
VMware vRealize Log Insight | >=4.7<4.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6980 refers to a vulnerability in VMware vRealize Log Insight that allows Admin users with view only permission to perform certain administrative functions.
CVE-2018-6980 has a severity rating of 7.2, which is considered high.
CVE-2018-6980 affects versions 4.7.x before 4.7.1 and 4.6.x before 4.6.2 of VMware vRealize Log Insight.
The vulnerability in CVE-2018-6980 can be exploited by Admin users with view only permission to perform unauthorized administrative functions.
Yes, VMware has released a patch to address the vulnerability in CVE-2018-6980. Users should update to versions 4.7.1 or 4.6.2 of VMware vRealize Log Insight.