CVE-2017-4951: VMware Airwatch

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

VMware AirWatch Console (9.2.x before 9.2.2 and 9.1.x before 9.1.5) contains a Cross Site Request Forgery vulnerability when accessing the App Catalog. An attacker may exploit this issue by tricking users into installing a malicious application on their devices.

Affected products

  • VMware Airwatch: from 9.1, before 9.1.5 (fixed in 9.1.5); from 9.2, before 9.2.2 (fixed in 9.2.2)

Published 2018-01-29. Last modified 2026-06-17.