

Rewterz Threat Advisory – CVE-2020-9484 – Apache Tomcat code execution
May 21, 2020
Rewterz Threat Alert – Iranian Chafer APT Targeted Air Transportation and Government in Kuwait and Saudi Arabia
May 21, 2020
Rewterz Threat Advisory – CVE-2020-9484 – Apache Tomcat code execution
May 21, 2020
Rewterz Threat Alert – Iranian Chafer APT Targeted Air Transportation and Government in Kuwait and Saudi Arabia
May 21, 2020Severity
High
Analysis Summary
An authenticated actor may be able to send malicious traffic to VMware Cloud Director which may lead to arbitrary remote code execution. This vulnerability can be exploited through the HTML5- and Flex-based UIs, the API Explorer interface and API access.
Impact
Code injection
Affected Vendors
VMware
Affected Products
VMware Cloud Director
Remediation
Refer to VMware security advisory for the list of affected products and upgraded patches.
https://www.vmware.com/security/advisories/VMSA-2020-0010.html