Authentication Bypass in vRealize Operations for Horizon Adapter by VMware
CVE-2020-3944

8.6HIGH

Key Information:

Vendor
Vmware
Vendor
CVE Published:
19 February 2020

Summary

The vRealize Operations for Horizon Adapter by VMware is susceptible to a significant security flaw due to improper trust store configuration. This vulnerability allows an unauthenticated remote attacker, with network access to vRealize Operations and the Horizon Adapter in operation, to bypass authentication mechanisms. This potentially exposes sensitive information and system functionality to malicious actors, highlighting the necessity for timely updates and appropriate security measures.

Affected Version(s)

vRealize Operations for Horizon Adapter 6.7.x prior to 6.7.1

vRealize Operations for Horizon Adapter 6.6.x prior to 6.6.1

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.