#VU15157 Session hijacking in AirWatch Console - CVE-2018-6979
Published: October 4, 2018 / Updated: October 5, 2018
AirWatch Console
VMware, Inc
Description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to SAML authentication bypass during device enrollment. A remote attacker can impersonate an authorized SAML session if certificate-based authentication is enabled and gain access to arbitrary data.