8.5

CVE-2016-7462

The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files or rename files via a crafted DiskFileItem in a relay-request payload that is mishandled during deserialization.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMwareVrealize Operations Version6.0.0
VMwareVrealize Operations Version6.1.0
VMwareVrealize Operations Version6.2.0a
VMwareVrealize Operations Version6.2.1
VMwareVrealize Operations Version6.3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.67% 0.804
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.5 3.1 4.7
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
nvd@nist.gov 7.5 8 7.8
AV:N/AC:L/Au:S/C:N/I:P/A:C
CWE-749 Exposed Dangerous Method or Function

The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.