VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF files via unspecified vectors.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1037326 | vdb entry third party advisory broken link |
http://www.vmware.com/security/advisories/VMSA-2016-0021.html | patch vendor advisory |
http://www.securityfocus.com/bid/94482 | vdb entry third party advisory |