VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add a malicious URL to an enrolled device's 'Links' page. Successful exploitation of this issue could result in an unsuspecting AWC user being redirected to a malicious URL.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1039750 | vdb entry third party advisory |
https://www.vmware.com/us/security/advisories/VMSA-2017-0016.html | patch vendor advisory |
http://www.securityfocus.com/bid/101772 | vdb entry third party advisory |