Critical severity9.1NVD Advisory· Published Mar 23, 2022· Updated Jun 17, 2026
CVE-2022-22951
CVE-2022-22951
Description
VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious actor with network access to the VMware App Control administration interface may be able to execute commands on the server due to improper input validation leading to remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- VMware/Carbon Black App Controldescription
(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:vmware:carbon_black_app_control:*:*:*:*:*:*:*:*range: >=8.5,<8.5.14
Patches
Vulnerability mechanics
References
1- www.vmware.com/security/advisories/VMSA-2022-0008.htmlnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.