CVE-2018-6978
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
vRealize Operations (7.x before 7.0.0.11287810, 6.7.x before 6.7.0.11286837 and 6.6.x before 6.6.1.11286876) contains a local privilege escalation vulnerability due to improper permissions of support scripts. Admin user of the vROps application with shell access may exploit this issue to elevate the privileges to root on a vROps machine. Note: the admin user (non-sudoer) should not be confused with root of the vROps machine.
vRealize Operations (versiones 7.x anteriores a la 7.0.0.11287810, 6.7.x anteriores a la 6.7.0.11286837 y 6.6.x anteriores a la 6.6.1.11286876) contiene una vulnerabilidad de escalado de privilegios local debido a permisos incorrectos de los scripts de soporte. El usuario Admin de la aplicación vROps con acceso shell podría explotar este problema para elevar los privilegios a root en una máquina vROps. Nota: el usuario admin (no sudo) no debería confundirse con el root de la máquina vROps.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-02-14 CVE Reserved
- 2018-12-18 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/106242 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.vmware.com/security/advisories/VMSA-2018-0031.html | 2019-10-03 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vmware Search vendor "Vmware" | Vrealize Operations Search vendor "Vmware" for product "Vrealize Operations" | >= 6.6.0 < 6.6.1.11286876 Search vendor "Vmware" for product "Vrealize Operations" and version " >= 6.6.0 < 6.6.1.11286876" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Vrealize Operations Search vendor "Vmware" for product "Vrealize Operations" | >= 6.7.0 < 6.7.0.11286837 Search vendor "Vmware" for product "Vrealize Operations" and version " >= 6.7.0 < 6.7.0.11286837" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Vrealize Operations Search vendor "Vmware" for product "Vrealize Operations" | >= 7.0.0 < 7.0.0.11287810 Search vendor "Vmware" for product "Vrealize Operations" and version " >= 7.0.0 < 7.0.0.11287810" | - |
Affected
|