Vulnerability Description
AirWatch by VMware On-Premise 7.3.x before 7.3.3.0 (FP3) allows remote authenticated users to obtain the organizational information and statistics from arbitrary tenants via vectors involving a direct object reference.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Airwatch | <= 7.3.3.0 |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2014/Dec/44
- http://www.vmware.com/security/advisories/VMSA-2014-0014.htmlVendor Advisory
- http://seclists.org/fulldisclosure/2014/Dec/44
- http://www.vmware.com/security/advisories/VMSA-2014-0014.htmlVendor Advisory
FAQ
What is CVE-2014-8372?
CVE-2014-8372 is a vulnerability with a CVSS score of 4.0 (MEDIUM). AirWatch by VMware On-Premise 7.3.x before 7.3.3.0 (FP3) allows remote authenticated users to obtain the organizational information and statistics from arbitrary tenants via vectors involving a direct...
How severe is CVE-2014-8372?
CVE-2014-8372 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-8372?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Airwatch.