CVE-2020-4006
Multiple VMware Products Command Injection Vulnerability
⚠ KEVEPSS 23.8%
描述
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the underlying operating system.
如何修補 CVE-2020-4006
OSV 沒有提供套件對應 — 請參考下方連結尋找廠商提供的建議。
CVE-2020-4006 正在被利用嗎?
是 — CVE-2020-4006 已列入 CISA Known Exploited Vulnerabilities (KEV) 清單,代表正在被實際利用,請立即修補。
受影響套件(0)
OSV 沒有提供套件對應。