VMware Xenon 1.x, prior to 1.5.4-CR71, 1.5.77, 1.5.4-CR62, 1.3.7-CR12, 1.1.0-CR0-3, 1.1.0-CR31,1.4.2-CR41, and 1.5.4_8, contains an authentication bypass vulnerability due to insufficient access controls for utility endpoints. Successful exploitation of this issue may result in information disclosure.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:vmware:xenon:*:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:xenon:1.1.0:cr0-3:*:*:*:*:*:*",
"cpe:2.3:a:vmware:xenon:1.1.0:cr3_1:*:*:*:*:*:*",
"cpe:2.3:a:vmware:xenon:1.3.7:cr1_2:*:*:*:*:*:*",
"cpe:2.3:a:vmware:xenon:1.4.2:cr4_1:*:*:*:*:*:*",
"cpe:2.3:a:vmware:xenon:1.5.4:cr2:*:*:*:*:*:*",
"cpe:2.3:a:vmware:xenon:1.5.4:cr3:*:*:*:*:*:*",
"cpe:2.3:a:vmware:xenon:1.5.4:cr4:*:*:*:*:*:*",
"cpe:2.3:a:vmware:xenon:1.5.4:cr5:*:*:*:*:*:*",
"cpe:2.3:a:vmware:xenon:1.5.4:cr6:*:*:*:*:*:*",
"cpe:2.3:a:vmware:xenon:1.5.4:cr6_1:*:*:*:*:*:*",
"cpe:2.3:a:vmware:xenon:1.5.4:cr6_2:*:*:*:*:*:*",
"cpe:2.3:a:vmware:xenon:1.5.4:cr7:*:*:*:*:*:*",
"cpe:2.3:a:vmware:xenon:1.5.4_8:*:*:*:*:*:*:*",
"cpe:2.3:a:vmware:xenon:1.5.7_7:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "1.0.0"
},
{
"last_affected": "1.5.3"
},
{
"last_affected": "1.1.0-cr0\\-3"
},
{
"last_affected": "1.1.0-cr3_1"
},
{
"last_affected": "1.3.7-cr1_2"
},
{
"last_affected": "1.4.2-cr4_1"
},
{
"last_affected": "1.5.4-cr2"
},
{
"last_affected": "1.5.4-cr3"
},
{
"last_affected": "1.5.4-cr4"
},
{
"last_affected": "1.5.4-cr5"
},
{
"last_affected": "1.5.4-cr6"
},
{
"last_affected": "1.5.4-cr6_1"
},
{
"last_affected": "1.5.4-cr6_2"
},
{
"last_affected": "1.5.4-cr7"
},
{
"last_affected": "1.5.4_8"
},
{
"last_affected": "1.5.7_7"
}
],
"vendor_product": "vmware:xenon",
"source": "CPE_FIELD"
}
]
}