情報源
CISA Current Activity
VMware Releases Workarounds for CVE-2020-4006
https://us-cert.cisa.gov/ncas/current-activity/2020/11/23/vmware-releases-workarounds-cve-2020-4006
概要
– VMware Workspace One Access (Access)
– VMware Workspace One Access Connector (Access Connector)
– VMware Identity Manager (vIDM)
– VMware Identity Manager Connector (vIDM Connector)
– VMware Cloud Foundation
– vRealize Suite Lifecycle Manager
関連文書 (日本語)
JVN
複数の VMware 製品に OS コマンドインジェクションの脆弱性
https://jvn.jp/vu/JVNVU97472624/
関連文書(英語)
VMSA-2020-0027.1
https://www.vmware.com/security/advisories/VMSA-2020-0027.html
VMware Workspace ONE Access and related components are vulnerable to command injection
https://kb.cert.org/vuls/id/724367
引用元:JPCERTコーディネーションセンター
「JPCERT/CC WEEKLY REPORT 2020-12-02」
https://www.jpcert.or.jp/wr/2020/wr204701.html