PT-2022-24501 · Vmware · Vmware Hyperic Server

CVE-2022-38651

·

Published

2022-11-12

·

Updated

2024-08-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VMware Hyperic Server version 5.8.6
Description A security filter misconfiguration exists, enabling a malicious party to bypass some authentication requirements when issuing requests to the server. This issue only affects products that are no longer supported by the maintainer.
Recommendations For version 5.8.6, consider disabling the vulnerable security filter as a temporary workaround until further guidance is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-38651

Affected Products

Vmware Hyperic Server