VYPR

Vrealize Automation

Sign in to watch

by VMware

CVEs (4)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2016-5336Cri0.649.80.02Aug 31, 2016VMware vRealize Automation 7.0.x before 7.1 allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2016-7460Cri0.599.10.02Dec 29, 2016The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVE-2016-5335Hig0.517.80.00Aug 31, 2016VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to obtain root access via unspecified vectors.
CVE-2015-2344Med0.355.40.00Mar 16, 2016Cross-site scripting (XSS) vulnerability in VMware vRealize Automation 6.x before 6.2.4 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.