← Back

CVE-2018-6979

nvd nist
Published: Oct 5, 2018Modified: Jun 17, 2026

JSON object

Loading...
7.4
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.2 / Impact: 5.2
Source: NVD

Description

The VMware Workspace ONE Unified Endpoint Management Console (A/W Console) 9.7.x prior to 9.7.0.3, 9.6.x prior to 9.6.0.7, 9.5.x prior to 9.5.0.16, 9.4.x prior to 9.4.0.22, 9.3.x prior to 9.3.0.25, 9.2.x prior to 9.2.3.27, and 9.1.x prior to 9.1.5.6 contains a SAML authentication bypass vulnerability which can be leveraged during device enrollment. This vulnerability may allow for a malicious actor to impersonate an authorized SAML session if certificate-based authentication is enabled. This vulnerability is also relevant if certificate-based authentication is not enabled, but the outcome of exploitation is limited to an information disclosure (Important Severity) in those cases.

Affected (7)

1 product
Airwatch Console
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
From 9.1.0.0 to 9.1.5.6
From 9.2.0.0 to 9.2.3.27
From 9.3.0.0 to 9.3.0.25
From 9.4.0.0 to 9.4.0.22
From 9.5.0.0 to 9.5.0.16
From 9.6.0.0 to 9.6.0.7
From 9.7.0.0 to 9.7.0.3

References (4)

Source: security@vmware.com
Third Party AdvisoryVDB Entry
Source: security@vmware.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.