SB2021030307 - Remote code execution in VMware View Planner



SB2021030307 - Remote code execution in VMware View Planner

Published: March 3, 2021

Security Bulletin ID SB2021030307
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Authorization (CVE-ID: CVE-2021-21978)

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to missing authorization within the View Planner Harness feature in logupload web application. A remote non-authenticated attacker can upload and execute arbitrary file on the system.

Successful exploitation of the vulnerability may allow an attacker to execute arbitrary code within the logupload container.


Remediation

Install update from vendor's website.