CVE-2019-5523: Critical severity vmware vcloud director vulnerability
VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerability in the Tenant and Provider Portals. Successful exploitation of this issue may allow a malicious actor to access the Tenant or Provider Portals by impersonating a currently logged in session.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-5523?
CVE-2019-5523 is a Remote Session Hijack vulnerability in VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update.
What is the severity of CVE-2019-5523?
CVE-2019-5523 has a severity rating of 9.8 (critical).
How does CVE-2019-5523 affect VMware vCloud Director?
CVE-2019-5523 affects VMware vCloud Director versions 9.5.x prior to 9.5.0.3.
How can CVE-2019-5523 be exploited?
CVE-2019-5523 can be exploited by a malicious actor to access the Tenant or Provider Portals by impersonating a currently logged-in user.
How can I fix CVE-2019-5523?
To fix CVE-2019-5523, update VMware vCloud Director to version 9.5.0.3 or later.