This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

VMware advisories/updates

146 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

VMSA-2018-0006 - vRealize Automation, vSphere Integrated Containers, and AirWatch Console updates address multiple security vulns
- https://www.vmware.com/security/advisories/VMSA-2018-0006.html
2018-01-26
Severity: Critical
CVE numbers: CVE-2017-4947, CVE-2017-4951
Summary: vRealize Automation, vSphere Integrated Containers, and AirWatch Console updates address multiple security vulnerabilities
Relevant Products:     
    vRealize Automation (vRA)
    vSphere Integrated Containers (VIC)
    VMware AirWatch Console (AWC)
Problem Description:
a. vRealize Automation and vSphere Integrated Containers deserialization vulnerability via Xenon
vRealize Automation and vSphere Integrated Containers contain a deserialization vulnerability via Xenon. Successful exploitation of this issue may allow remote attackers to execute arbitrary code on the appliance.
b. VMware AirWatch Console Cross Site Request Forgery (CSRF)
VMware AirWatch Console contains a Cross Site Request Forgery vulnerability when accessing the App Catalog. An attacker may exploit this issue by tricking users into installing a malicious application on their devices…
Solution: Please review the patch/release notes for your product and version and verify the checksum of your downloaded file.
> VMware vRealize Automation 7.3
Downloads and Documentation:  
- https://my.vmware.com/web/vmware/info/slug/infrastructure_operations_management/vmware_vrealize_automation/7_3
- https://docs.vmware.com/en/vRealize-Automation/index.html
> VMware vRealize Automation 7.2
Downloads and Documentation:  
- https://my.vmware.com/web/vmware/info/slug/infrastructure_operations_management/vmware_vrealize_automation/7_2
- https://docs.vmware.com/en/vRealize-Automation/index.html
> VMware vSphere Integrated Containers 1.3
Downloads and Documentation:
- https://my.vmware.com/web/vmware/info/slug/datacenter_cloud_infrastructure/vmware_vsphere_integrated_containers/1_3
- https://www.vmware.com/support/pubs/vsphere-integrated-containers-pubs.html
> VMware AirWatch Console 9.2.2
Downloads and Documentation:
- https://support.air-watch.com/articles/115015625647
> VMware AirWatch Console 9.1.5
Downloads and Documentation:  
- https://my.air-watch.com/products/AirWatch-Console/Windows/v9.1.0.0
___

- https://www.us-cert.gov/ncas/current-activity/2018/01/26/VMware-Releases-Security-Updates
Jan 26, 2018
 

:ph34r: :ph34r:

FYI…

VMSA-2018-0007 - VMware Virtual Appliance updates address side-channel analysis due to speculative execution
- https://www.vmware.com/security/advisories/VMSA-2018-0007.html
2018-02-08
Severity: Important
Summary: VMware Virtual Appliance updates address side-channel analysis due to speculative execution
Note: This document will focus on VMware Virtual Appliances which are affected by the known variants of CVE-2017-5753, CVE-2017-5715, and CVE-2017-5754.
For more information please see Knowledge Base article 52264:
- https://kb.vmware.com/s/article/52264
These mitigations are part of the Operating System-Specific Mitigations category described in VMware Knowledge Base article 52245:
- https://kb.vmware.com/s/article/52245
Relevant Products
 vCloud Usage Meter (UM)
 Identity Manager (vIDM)
 vCenter Server (vCSA)
 vSphere Data Protection (VDP)
 vSphere Integrated Containers (VIC)
 vRealize Automation (vRA)
Problem Description: VMware Virtual Appliance Mitigations for Bounds-Check bypass, Branch Target Injection, and Rogue data cache load issues.
CPU data cache timing can be abused to efficiently leak information out of mis-speculated CPU execution, leading to (at worst) arbitrary virtual memory read vulnerabilities across local security boundaries in various contexts. (Speculative execution is an automatic and inherent CPU performance optimization used in all modern processors.) Successful exploitation may allow for information disclosure.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifiers CVE-2017-5753 (Bounds Check bypass), CVE-2017-5715 (Branch Target Injection), CVE-2017-5754 (Rogue data cache load) to these issues…
Solution: Please review the patch/release notes for your product and version and verify the checksum of your downloaded file.
> vSphere Integrated Containers 1.3.1
Downloads and Documentation:
- https://my.vmware.com/group/vmware/get-download?downloadGroup=VIC131
> References:
- http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5753
- http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5715
- http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5754
- https://kb.vmware.com/kb/52264
- https://kb.vmware.com/kb/52245
- https://kb.vmware.com/kb/52467
- https://kb.vmware.com/kb/52284
- https://kb.vmware.com/kb/52312
- https://kb.vmware.com/kb/52377
- https://kb.vmware.com/kb/52497
 

:ph34r: :ph34r: