Rewterz
Rewterz Threat Advisory – CVE-2020-9484 – Apache Tomcat code execution
May 21, 2020
Rewterz
Rewterz Threat Alert – Iranian Chafer APT Targeted Air Transportation and Government in Kuwait and Saudi Arabia
May 21, 2020

Rewterz Threat Advisory – CVE-2020-3956 – VMware Cloud Director updates address Vulnerability

Severity

High

Analysis Summary

An authenticated actor may be able to send malicious traffic to VMware Cloud Director which may lead to arbitrary remote code execution. This vulnerability can be exploited through the HTML5- and Flex-based UIs, the API Explorer interface and API access.

Impact

Code injection

Affected Vendors

VMware

Affected Products

VMware Cloud Director

Remediation

Refer to VMware security advisory for the list of affected products and upgraded patches.

https://www.vmware.com/security/advisories/VMSA-2020-0010.html