CVE-2018-6960
VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability that may allow an attacker to bypass two-factor authentication. Note: In order to exploit this issue, an attacker must have a legitimate account on Horizon DaaS.
Date published : 2018-04-20
http://www.securityfocus.com/bid/103938
https://www.vmware.com/security/advisories/VMSA-2018-0010.html