SB2018111409 - Authorization bypass in VMware vRealize Log Insight
Published: November 14, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Authorization bypass (CVE-ID: CVE-2018-6980)
The vulnerability allows a remote administrative attacker to bypass authorization on the target system.
The vulnerability exists due to improper authorization in the user registration method. An Admin attacker with view only permission can perform certain administrative functions not allowed to perform.
Remediation
Install update from vendor's website.