Vmware
Vmware Vrealize LOG Insight: vulnerabilidades y CVE
Vmware Vrealize LOG Insight tiene 15 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-31711 | Media (5.3) | 24% | — | 26 ene 2023 | VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and application information without authentication. |
| CVE-2022-31710 | Alta (7.5) | 1.5% | — | 26 ene 2023 | vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrusted data which could result in a denial of service. |
| CVE-2022-31706 | Crítica (9.8) | 87% | — | 26 ene 2023 | The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution. |
| CVE-2022-31704 | Crítica (9.8) | 81% | — | 26 ene 2023 | The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in remote code… |
| CVE-2022-31703 | Alta (7.5) | 1.9% | — | 14 dic 2022 | The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution. |
| CVE-2022-31655 | Media (5.4) | 0.43% | — | 12 jul 2022 | VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in alerts. |
| CVE-2022-31654 | Media (5.4) | 0.43% | — | 12 jul 2022 | VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in configurations. |
| CVE-2021-22035 | Media (4.3) | 0.57% | — | 13 oct 2021 | VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interactive analytics export function. An authenticated malicious actor with non-administrative privileges… |
| CVE-2021-22021 | Media (5.4) | 0.47% | — | 30 ago 2021 | VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user input validation. An attacker with user privileges may be able to inject a malicious payload via… |
| CVE-2020-3954 | Media (6.1) | 0.79% | — | 15 abr 2020 | Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation. |
| CVE-2020-3953 | Media (4.8) | 0.65% | — | 15 abr 2020 | Cross Site Scripting (XSS) vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation. |
| CVE-2018-6980 | Alta (7.2) | 1.4% | — | 13 nov 2018 | VMware vRealize Log Insight (4.7.x before 4.7.1 and 4.6.x before 4.6.2) contains a vulnerability due to improper authorization in the user registration method. Successful exploitation of this issue may allow Admin users… |
| CVE-2016-5332 | Media (5.3) | 3.0% | — | 31 ago 2016 | Directory traversal vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.6.0 allows remote attackers to read arbitrary files via unspecified vectors. |
| CVE-2016-2082 | Alta (8.8) | 0.63% | — | 3 jul 2016 | Cross-site request forgery (CSRF) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. |
| CVE-2016-2081 | Media (6.1) | 0.77% | — | 3 jul 2016 | Cross-site scripting (XSS) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |