Vulnerability Description
VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Workspace One Boxer | < 5.13.1 |
| Vmware | Workspace One Content | < 3.21 |
| Vmware | Workspace One Intelligent Hub | < 19.11.1 |
| Vmware | Workspace One Notebook | < 1.2.1 |
| Vmware | Workspace One People | < 1.3.2 |
| Vmware | Workspace One Piv-D Manager | < 1.4.2 |
| Vmware | Workspace One Sdk | < 1.4.1 |
| Vmware | Workspace One Sdk \(Objective-C\) | >= 5.9.9.7, < 5.9.9.8 |
| Vmware | Workspace One Web | < 7.10.8 |
Related Weaknesses (CWE)
References
- https://www.vmware.com/security/advisories/VMSA-2020-0001.htmlVendor Advisory
- https://www.vmware.com/security/advisories/VMSA-2020-0001.htmlVendor Advisory
FAQ
What is CVE-2020-3940?
CVE-2020-3940 is a vulnerability with a CVSS score of 5.9 (MEDIUM). VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability.
How severe is CVE-2020-3940?
CVE-2020-3940 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-3940?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Workspace One Boxer, Vmware Workspace One Content, Vmware Workspace One Intelligent Hub, Vmware Workspace One Notebook, Vmware Workspace One People.