CVE-2020-3943: VMware vRealize remote code execution vulnerability alert

Recently, VMware released a security update VMSA-2020-0003. One of them is the CVE number CVE-2020-3943 serious vulnerabilities. "Applies to Horizon Adapter of vRealize Operations using JMX RMI service is not securely configured. VMware has been assessing the severity of this problem" within the critical "severity of the range, the maximum CVSSv3 basic score of 9.0. In the case of Horizon adapter running with , you could execute arbitrary code in vRealize Operations in remote unauthenticated attacker network access vRealize Operations of verification. "

Affected versions

  • vRealize Operations for Horizon Adapter <= 6.6.0
  • vRealize Operations for Horizon Adapter <= 6.7.0

Unaffected version

  • vRealize Operations for Horizon Adapter 6.6.1
  • vRealize Operations for Horizon Adapter 6.7.1

Guess you like

Origin www.linuxidc.com/Linux/2020-02/162425.htm