VMware AirWatch Console (9.2.x before 9.2.2 and 9.1.x before 9.1.5) contains a Cross Site Request Forgery vulnerability when accessing the App Catalog. An attacker may exploit this issue by tricking users into installing a malicious application on their devices.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://www.vmware.com/security/advisories/VMSA-2018-0006.html | patch vendor advisory |
http://www.securitytracker.com/id/1040288 | vdb entry third party advisory |
http://www.securityfocus.com/bid/102849 | vdb entry third party advisory |