Vmware
Vmware Vrealize Suite Lifecycle Manager: vulnerabilidades y CVE
Vmware Vrealize Suite Lifecycle Manager tiene 21 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 4 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses0
Críticas4
Explotadas activamente4
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-22960 | Alta (7.8) | 36% | ⚠ Explotación activa | 13 abr 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate… |
| CVE-2022-22954 | Crítica (9.8) | 100% | ⚠ Explotación activa | 11 abr 2022 | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection… |
| CVE-2021-21975 | Alta (7.5) | 78% | ⚠ Explotación activa | 31 mar 2021 | Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request… |
| CVE-2020-4006 | Crítica (9.1) | 17% | ⚠ Explotación activa | 23 nov 2020 | VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-22973 | Alta (7.8) | 2.4% | — | 20 may 2022 | VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'. |
| CVE-2022-22972 | Crítica (9.8) | 56% | — | 20 may 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain… |
| CVE-2022-22961 | Media (5.3) | 0.85% | — | 13 abr 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of… |
| CVE-2022-22960 | Alta (7.8) | 36% | ⚠ Explotación activa | 13 abr 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate… |
| CVE-2022-22959 | Media (4.3) | 0.51% | — | 13 abr 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally… |
| CVE-2022-22958 | Alta (7.2) | 3.1% | — | 13 abr 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger… |
| CVE-2022-22957 | Alta (7.2) | 24% | — | 13 abr 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger… |
| CVE-2022-22954 | Crítica (9.8) | 100% | ⚠ Explotación activa | 11 abr 2022 | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection… |
| CVE-2021-22035 | Media (4.3) | 0.57% | — | 13 oct 2021 | VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interactive analytics export function. An authenticated malicious actor with non-administrative privileges… |
| CVE-2021-22033 | Baja (2.7) | 0.61% | — | 13 oct 2021 | Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability. |
| CVE-2021-22003 | Alta (7.5) | 0.99% | — | 31 ago 2021 | VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login… |
| CVE-2021-22002 | Crítica (9.8) | 1.2% | — | 31 ago 2021 | VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443… |
| CVE-2021-22027 | Alta (7.5) | 1.2% | — | 30 ago 2021 | The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a… |
| CVE-2021-22026 | Alta (7.5) | 1.1% | — | 30 ago 2021 | The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a… |
| CVE-2021-22025 | Alta (7.5) | 0.81% | — | 30 ago 2021 | The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unauthenticated malicious actor with network access to the vRealize… |
| CVE-2021-22024 | Alta (7.5) | 1.0% | — | 30 ago 2021 | The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read any log… |
| CVE-2021-22023 | Alta (7.2) | 1.00% | — | 30 ago 2021 | The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to vRealize Operations Manager API may be able to modify other users… |
| CVE-2021-22022 | Media (4.9) | 1.1% | — | 30 ago 2021 | The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor with administrative access to vRealize Operations Manager API can read any arbitrary file on server… |
| CVE-2021-21983 | Media (6.5) | 69% | — | 31 mar 2021 | Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files… |
| CVE-2021-21975 | Alta (7.5) | 78% | ⚠ Explotación activa | 31 mar 2021 | Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request… |
| CVE-2020-4006 | Crítica (9.1) | 17% | ⚠ Explotación activa | 23 nov 2020 | VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.