CVE-2017-4947

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
29/01/2018
Last modified:
17/09/2024

Description

VMware vRealize Automation (7.3 and 7.2) and vSphere Integrated Containers (1.x before 1.3) contain a deserialization vulnerability via Xenon. Successful exploitation of this issue may allow remote attackers to execute arbitrary code on the appliance.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:vrealize_automation:7.2.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:vrealize_automation:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:vsphere_integrated_containers:*:*:*:*:*:*:*:* 1.3.0 (excluding)