CVE Vulnerabilities

CVE-2016-7462

Published: Dec 29, 2016 | Modified: Apr 12, 2025
CVSS 3.x
8.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:S/C:N/I:P/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files or rename files via a crafted DiskFileItem in a relay-request payload that is mishandled during deserialization.

Affected Software

NameVendorStart VersionEnd Version
Vrealize_operationsVmware6.0.0 (including)6.0.0 (including)
Vrealize_operationsVmware6.1.0 (including)6.1.0 (including)
Vrealize_operationsVmware6.2.0a (including)6.2.0a (including)
Vrealize_operationsVmware6.2.1 (including)6.2.1 (including)
Vrealize_operationsVmware6.3.0 (including)6.3.0 (including)

References