« Volver al listado

Vmware

Vmware Vrealize Suite Lifecycle Manager: vulnerabilidades y CVE

Vmware Vrealize Suite Lifecycle Manager tiene 21 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 4 figuran en el catálogo de explotación activa de CISA.

CVE21
Últimos 12 meses0
Críticas4
Explotadas activamente4

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2022-22960Alta (7.8)36%⚠ Explotación activa13 abr 2022
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate…
CVE-2022-22954Crítica (9.8)100%⚠ Explotación activa11 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection…
CVE-2021-21975Alta (7.5)78%⚠ Explotación activa31 mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request…
CVE-2020-4006Crítica (9.1)17%⚠ Explotación activa23 nov 2020
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2022-22973Alta (7.8)2.4%—20 may 2022
VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.
CVE-2022-22972Crítica (9.8)56%—20 may 2022
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain…
CVE-2022-22961Media (5.3)0.85%—13 abr 2022
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of…
CVE-2022-22960Alta (7.8)36%⚠ Explotación activa13 abr 2022
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate…
CVE-2022-22959Media (4.3)0.51%—13 abr 2022
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally…
CVE-2022-22958Alta (7.2)3.1%—13 abr 2022
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger…
CVE-2022-22957Alta (7.2)24%—13 abr 2022
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger…
CVE-2022-22954Crítica (9.8)100%⚠ Explotación activa11 abr 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection…
CVE-2021-22035Media (4.3)0.57%—13 oct 2021
VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interactive analytics export function. An authenticated malicious actor with non-administrative privileges…
CVE-2021-22033Baja (2.7)0.61%—13 oct 2021
Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability.
CVE-2021-22003Alta (7.5)0.99%—31 ago 2021
VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login…
CVE-2021-22002Crítica (9.8)1.2%—31 ago 2021
VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443…
CVE-2021-22027Alta (7.5)1.2%—30 ago 2021
The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a…
CVE-2021-22026Alta (7.5)1.1%—30 ago 2021
The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a…
CVE-2021-22025Alta (7.5)0.81%—30 ago 2021
The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unauthenticated malicious actor with network access to the vRealize…
CVE-2021-22024Alta (7.5)1.0%—30 ago 2021
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read any log…
CVE-2021-22023Alta (7.2)1.00%—30 ago 2021
The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to vRealize Operations Manager API may be able to modify other users…
CVE-2021-22022Media (4.9)1.1%—30 ago 2021
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor with administrative access to vRealize Operations Manager API can read any arbitrary file on server…
CVE-2021-21983Media (6.5)69%—31 mar 2021
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files…
CVE-2021-21975Alta (7.5)78%⚠ Explotación activa31 mar 2021
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request…
CVE-2020-4006Crítica (9.1)17%⚠ Explotación activa23 nov 2020
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter2
  2. T1190 Exploit Public-Facing Application2
  3. T1068 Exploitation for Privilege Escalation1
  4. T1210 Exploitation of Remote Services1
  5. T1222 File and Directory Permissions Modification1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Vmware