VYPR

Vrealize Suite Lifecycle Manager

by VMware

CVEs (21)

  • CVE-2022-22954CriKEVApr 11, 2022
    risk 0.93cvss 9.8epss 1.00

    VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

  • CVE-2021-21975HigKEVMar 31, 2021
    risk 0.76cvss 7.5epss 0.78

    Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.

  • CVE-2020-4006CriKEVNov 23, 2020
    risk 0.73cvss 9.1epss 0.24

    VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.

  • CVE-2022-22960HigKEVApr 13, 2022
    risk 0.69cvss 7.8epss 0.36

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.

  • CVE-2022-22972CriMay 20, 2022
    risk 0.68cvss 9.8epss 0.56

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

  • CVE-2021-22002CriAug 31, 2021
    risk 0.64cvss 9.8epss 0.01

    VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443 could tamper with host headers to facilitate access to the…

  • CVE-2022-22957HigApr 13, 2022
    risk 0.52cvss 7.2epss 0.23

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which…

  • CVE-2022-22973HigMay 20, 2022
    risk 0.51cvss 7.8epss 0.02

    VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.

  • CVE-2021-21983MedMar 31, 2021
    risk 0.51cvss 6.5epss 0.69

    Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating…

  • CVE-2021-22003HigAug 31, 2021
    risk 0.49cvss 7.5epss 0.01

    VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based on lockout policy…

  • CVE-2021-22027HigAug 30, 2021
    risk 0.49cvss 7.5epss 0.01

    The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack leading to information…

  • CVE-2021-22026HigAug 30, 2021
    risk 0.49cvss 7.5epss 0.01

    The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack leading to information…

  • CVE-2021-22025HigAug 30, 2021
    risk 0.49cvss 7.5epss 0.01

    The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can add new nodes to existing vROps cluster.

  • CVE-2021-22024HigAug 30, 2021
    risk 0.49cvss 7.5epss 0.01

    The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read any log file resulting in sensitive information disclosure.

  • CVE-2022-22958HigApr 13, 2022
    risk 0.47cvss 7.2epss 0.03

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which…

  • CVE-2021-22023HigAug 30, 2021
    risk 0.47cvss 7.2epss 0.01

    The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to vRealize Operations Manager API may be able to modify other users information leading to an account takeover.

  • CVE-2022-22961MedApr 13, 2022
    risk 0.35cvss 5.3epss 0.01

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the target system. Successful exploitation of this issue can…

  • CVE-2021-22022MedAug 30, 2021
    risk 0.32cvss 4.9epss 0.01

    The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor with administrative access to vRealize Operations Manager API can read any arbitrary file on server leading to information disclosure.

  • CVE-2022-22959MedApr 13, 2022
    risk 0.28cvss 4.3epss 0.01

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally validate a malicious JDBC URI.

  • CVE-2021-22035MedOct 13, 2021
    risk 0.28cvss 4.3epss 0.01

    VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interactive analytics export function. An authenticated malicious actor with non-administrative privileges may be able to embed untrusted data prior to exporting a CSV…

Page 1 of 2