6.8

CVE-2014-1211

Cross-site request forgery (CSRF) vulnerability in VMware vCloud Director 5.1.x before 5.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Vcloud Director Version 5.1.0
VMware ≫ Vcloud Director Version 5.1.1
VMware ≫ Vcloud Director Version 5.1.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.29% 0.665
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

http://www.vmware.com/security/advisories/VMSA-2014-0001.html
Vendor Advisory
http://osvdb.org/102198
http://www.securityfocus.com/bid/64993
http://www.securitytracker.com/id/1029645
https://exchange.xforce.ibmcloud.com/vulnerabilities/90560