CVE-2014-8372 describes a direct object reference vulnerability in AirWatch by VMware On-Premise 7.3.x before 7.3.3.0 (FP3). This flaw allows remote authenticated users to access sensitive organizational information and statistics from other tenants. With a CVSS score of 4.0, it has low severity, requiring authentication but with low attack complexity, primarily impacting confidentiality. There is no evidence of active exploitation, nor are public exploit codes like Metasploit or ExploitDB modules available, though it has received limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.3.3.0CPE matchmatch criteria | cpe:2.3:a:vmware:airwatch:*:*:*:*:*:*:*:* | ||
7.3.0.0CPE matchmatch criteria | cpe:2.3:a:vmware:airwatch:7.3.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.