Vmware
Vmware Vrealize Operations: vulnerabilidades y CVE
Vmware Vrealize Operations tiene 18 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-20879 | Media (6.7) | 0.18% | — | 12 may 2023 | VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privileges in the Aria Operations application can gain root access to the underlying operating system. |
| CVE-2023-20878 | Alta (7.2) | 1.0% | — | 12 may 2023 | VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system. |
| CVE-2023-20877 | Alta (8.8) | 0.65% | — | 12 may 2023 | VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation. |
| CVE-2023-20856 | Alta (8.8) | 0.40% | — | 1 feb 2023 | VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of the authenticated victim user. |
| CVE-2022-31708 | Media (4.9) | 0.82% | — | 16 dic 2022 | vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.4. |
| CVE-2022-31707 | Alta (7.2) | 0.99% | — | 16 dic 2022 | vRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2. |
| CVE-2022-31682 | Media (4.9) | 0.64% | — | 11 oct 2022 | VMware Aria Operations contains an arbitrary file read vulnerability. A malicious actor with administrative privileges may be able to read arbitrary files containing sensitive data. |
| CVE-2022-31675 | Alta (7.5) | 0.81% | — | 10 ago 2022 | VMware vRealize Operations contains an authentication bypass vulnerability. An unauthenticated malicious actor with network access may be able to create a user with administrative privileges. |
| CVE-2022-31674 | Media (4.3) | 0.63% | — | 10 ago 2022 | VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can access log files that lead to information disclosure. |
| CVE-2022-31673 | Alta (8.8) | 1.6% | — | 10 ago 2022 | VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can create and leak hex dumps, leading to information disclosure. Successful exploitation… |
| CVE-2022-31672 | Alta (7.2) | 0.64% | — | 10 ago 2022 | VMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network access can escalate privileges to root. |
| CVE-2021-22033 | Baja (2.7) | 0.61% | — | 13 oct 2021 | Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability. |
| CVE-2020-3945 | Alta (7.5) | 1.4% | — | 19 feb 2020 | vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) contains an information disclosure vulnerability due to incorrect pairing implementation between the vRealize Operations for… |
| CVE-2020-3944 | Alta (8.6) | 1.5% | — | 19 feb 2020 | vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) has an improper trust store configuration leading to authentication bypass. An unauthenticated remote attacker who has network… |
| CVE-2020-3943 | Crítica (9.8) | 2.3% | — | 19 feb 2020 | vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX RMI service which is not securely configured. An unauthenticated remote attacker who has network access to vRealize… |
| CVE-2018-6978 | Media (6.7) | 0.33% | — | 18 dic 2018 | vRealize Operations (7.x before 7.0.0.11287810, 6.7.x before 6.7.0.11286837 and 6.6.x before 6.6.1.11286876) contains a local privilege escalation vulnerability due to improper permissions of support scripts. Admin user… |
| CVE-2016-7462 | Alta (8.5) | 2.0% | — | 29 dic 2016 | The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files or rename files via a crafted DiskFileItem in a relay-request payload… |
| CVE-2016-7457 | Crítica (10) | 3.2% | — | 29 dic 2016 | VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to gain privileges, or halt and remove virtual machines, via unspecified vectors. |