Privilege escalation in VMware Identity Manager and Aria Automation (formerly vRealize Automation) - CVE-2016-5335
Published: August 27, 2016 / Updated: November 22, 2018
VMware Identity Manager
Aria Automation (formerly vRealize Automation)
Detailed vulnerability description
The vulnerability allows a local user to gain elevated privileges.
The vulnerability exists due to unknown error in Identity Manager and vRealize Automation. A local user can elevate his privileges to root.
Successful exploitation of this vulnerability will allow a local user to gain root privileges and complete control over vulnerable appliance.
How to mitigate CVE-2016-5335
Apply patches for VMware Identity Manager 2.7 and vRealize Automation 7.1.