CVE-2018-6980

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/11/2018
Last modified:
03/10/2019

Description

VMware vRealize Log Insight (4.7.x before 4.7.1 and 4.6.x before 4.6.2) contains a vulnerability due to improper authorization in the user registration method. Successful exploitation of this issue may allow Admin users with view only permission to perform certain administrative functions which they are not allowed to perform.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:vrealize_log_insight:*:*:*:*:*:*:*:* 4.6 (including) 4.6.2 (excluding)
cpe:2.3:a:vmware:vrealize_log_insight:*:*:*:*:*:*:*:* 4.7 (including) 4.7.1 (excluding)