Vulnerability Name: | CVE-2017-4922 (CCN-129547) | ||||||||||||
Assigned: | 2016-12-26 | ||||||||||||
Published: | 2017-07-27 | ||||||||||||
Updated: | 2017-08-03 | ||||||||||||
Summary: | VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the service startup script using world writable directories as temporary storage for critical information. Successful exploitation of this issue may allow unprivileged host users to access certain critical information when the service gets restarted. | ||||||||||||
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) 5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-4922 Source: BID Type: Third Party Advisory, VDB Entry 100012 Source: CCN Type: BID-100012 VMware vCenter Server CVE-2017-4922 Local Information Disclosure Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1039013 Source: XF Type: UNKNOWN vmware-cve20174922-info-disc(129547) Source: CCN Type: VMware Security Advisory VMSA-2017-0013 VMware vCenter Server and Tools updates resolve multiple security vulnerabilities Source: CONFIRM Type: Patch, Vendor Advisory https://www.vmware.com/security/advisories/VMSA-2017-0013.html | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |