7.5
CVSSv2

CVE-2016-7462

Published: 29/12/2016 Updated: 28/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 7.8 | Exploitability Score: 8
CVSS v3 Base Score: 8.5 | Impact Score: 4.7 | Exploitability Score: 3.1
VMScore: 670
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:C

Vulnerability Summary

The Suite REST API in VMware vRealize Operations (aka vROps) 6.x prior to 6.4.0 allows remote authenticated users to write arbitrary content to files or rename files via a crafted DiskFileItem in a relay-request payload that is mishandled during deserialization.

Vulnerable Product Search on Vulmon Subscribe to Product

vmware vrealize operations 6.2.1

vmware vrealize operations 6.3.0

vmware vrealize operations 6.1.0

vmware vrealize operations 6.2.0a

vmware vrealize operations 6.0.0