Learn about CVE-2020-3945, an information disclosure vulnerability in vRealize Operations for Horizon Adapter, allowing unauthorized access to sensitive data. Find mitigation steps and patching details here.
vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) contains an information disclosure vulnerability due to incorrect pairing implementation between the vRealize Operations for Horizon Adapter and Horizon View. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may obtain sensitive information.
Understanding CVE-2020-3945
This CVE identifies an information disclosure vulnerability in vRealize Operations for Horizon Adapter.
What is CVE-2020-3945?
CVE-2020-3945 is an information disclosure vulnerability in vRealize Operations for Horizon Adapter, allowing unauthenticated remote attackers to access sensitive information.
The Impact of CVE-2020-3945
The vulnerability can lead to unauthorized access to sensitive data by attackers with network access to vRealize Operations.
Technical Details of CVE-2020-3945
vRealize Operations for Horizon Adapter is affected by an information disclosure vulnerability.
Vulnerability Description
The vulnerability arises from incorrect pairing implementation between the vRealize Operations for Horizon Adapter and Horizon View.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Immediate Steps to Take:
Long-Term Security Practices:
Patching and Updates: