AirWatch by VMware On-Premise 7.3.x before 7.3.3.0 (FP3) allows remote authenticated users to obtain the organizational information and statistics from arbitrary tenants via vectors involving a direct object reference.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.vmware.com/security/advisories/VMSA-2014-0014.html | vendor advisory |
http://seclists.org/fulldisclosure/2014/Dec/44 | mailing list |