VMware vShield Manager Permits Cross-Site Request Attacks
|
|
SecurityTracker Alert ID: 1026815 |
|
SecurityTracker URL: http://securitytracker.com/id/1026815
|
|
CVE Reference:
CVE-2012-1514
(Links to External Site)
|
Date: Mar 16 2012
|
Impact:
Execution of arbitrary code via network, Modification of user information
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): vShield Manager 4.0, 4.1
|
Description:
A vulnerability was reported in VMware vShield Manager. A remote user can conduct cross-site request forgery attacks.
A remote user can create a specially crafted URL that, when loaded by a target user, will take actions on the target site acting as the target user.
Frans Pehrson of Xxor AB and Claudio Criscione independently reported this vulnerability.
|
Impact:
A remote user can take actions on the site acting as the target user.
|
Solution:
The vendor has issued a fix (1.0.1 Update 2, 4.1.0 Update 2).
The vendor's advisory is available at:
http://www.vmware.com/security/advisories/VMSA-2012-0005.html
|
Vendor URL: www.vmware.com/security/advisories/VMSA-2012-0005.html (Links to External Site)
|
Cause:
Access control error
|
Underlying OS:
Linux (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Fri, 16 Mar 2012 07:16:47 +0000
Subject: VMware
|
http://www.vmware.com/security/advisories/VMSA-2012-0005.html
d. vShield Manager Cross-Site Request Forgery vulnerability
The vShield Manager (vSM) interface has a Cross-Site Request
Forgery vulnerability. If an attacker can convince an
authenticated user to visit a malicious link, the attacker may
force the victim to forward an authenticated request to the
server.
VMware would like to thank Frans Pehrson of Xxor AB
(www.xxor.se) and Claudio Criscione for independently reporting
this issue to us
The Common Vulnerabilities and Exposures project (cve.mitre.org)
has assigned the name CVE-2012-1514 to this issue.
VMware Product Running Replace with/
Product Version on Apply Patch
============= ======= ======= =================
vSM 5.0 Linux not affected
vSM 4.1 Linux vSM 4.1.0 Update 2
vSM 4.0 Linux vSM 1.0.1 Update 2
|
|