CVE-2021-21990 Information

Description

VMware Workspace one UEM console (2102 prior to 21.2.0.8 2101 prior to 21.1.0.14 2011 prior to 20.11.0.27 2010 prior to 20.10.0.162008 prior to 20.8.0.28 2007 prior to 20.7.0.142006 prior to 20.6.0.19 2005 prior to 20.5.0.46 2004 prior to 20.4.0.21 2003 prior to 20.3.0.23 2001 prior to 20.1.0.32 1912 prior to 19.12.0.24) contain a cross-site scripting vulnerability. VMware Workspace ONE UEM console does not validate incoming requests during device enrollment after leading to rendering of unsanitized input on the user device in response.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Reference

https://www.vmware.com/security/advisories/VMSA-2021-0008.html https://herolab.usd.de/security-advisories/usd-2021-0008/

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.1

Share on: