CVE-2020-3945
HIGHvRealize Operations for Horizon Adapter <6.7.1-6.6.1 - Info Disclosure
Title source: llmDescription
vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) contains an information disclosure vulnerability due to incorrect pairing implementation between the vRealize Operations for Horizon Adapter and Horizon View. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may obtain sensitive information
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
https://www.vmware.com/security/advisories/VMSA-2020-0003.html
Scores
CVSS v3
7.5
EPSS
0.0044
EPSS Percentile
63.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
Status
published
Products (1)
vmware/vrealize_operations
6.6.0 - 6.6.1
Published
Feb 19, 2020
Tracked Since
Feb 18, 2026