98939vdb entry
http://www.securityfocus.com/bid/98939 CVE-2017-4914
CRITICAL
VMware vSphere Data Protection 5.x/6.x - Java Deserialization
Record summary
CVE-2017-4914 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote attacker to execute commands on the appliance.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
vSphere Data Protection (VDP)Browse VMware / vSphere Data Protection (VDP) | CVE List | 6.1.x | affected |
| 6.0.x | affected | ||
| 5.8.x | affected | ||
| 5.5.x | affected |
Proofs of concept
1Catalogued exploits
ExploitDBVMware vSphere Data Protection 5.x/6.x - Java DeserializationExploitDB exploitby Kelly CorrellNot analyzed1 file
References
51038617vdb entry
http://www.securitytracker.com/id/1038617 vmware.comConfirmation
http://www.vmware.com/security/advisories/VMSA-2017-0010.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-4914 42152exploit
https://www.exploit-db.com/exploits/42152