« Volver al listado

Vmware

Vmware Security: vulnerabilidades y CVE

Vmware Security tiene 6 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE6
Últimos 12 meses2
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-34263Crítica (9.6)0.62%—12 may 2026
Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, resulting in arbitrary server-side code execution, leading to high impact on…
CVE-2025-22234Media (5.3)0.40%—22 ene 2026
The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvider. This can allow attackers to infer valid usernames or other authentication behavior via…
CVE-2025-41249Alta (7.5)0.46%—16 sept 2025
The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such…
CVE-2025-41232Crítica (9.1)0.62%—21 may 2025
Spring Security Aspects may not correctly locate method security annotations on private methods. This can cause an authorization bypass. Your application may be affected by this if the following are true: You are not…
CVE-2025-22235Alta (7.3)0.43%—28 abr 2025
EndpointRequest.to() creates a matcher for null/** if the actuator endpoint, for which the EndpointRequest has been created, is disabled or not exposed. Your application may be affected by this if all the following…
CVE-2024-38821Crítica (9.1)1.7%—28 oct 2024
Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under certain circumstances. For this to impact an application, all of the following must be true:

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application4
  2. T1005 Data from Local System1
  3. T1059 Command and Scripting Interpreter1
  4. T1078 Valid Accounts1
  5. T1203 Exploitation for Client Execution1
  6. T1552.001 Credentials In Files1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Vmware