CVE-2023-20879
- EPSS 0.05%
- Veröffentlicht 12.05.2023 21:15:09
- Zuletzt bearbeitet 27.01.2025 17:15:10
VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privileges in the Aria Operations application can gain root access to the underlying operating system.
CVE-2023-20878
- EPSS 0.56%
- Veröffentlicht 12.05.2023 21:15:09
- Zuletzt bearbeitet 27.01.2025 18:15:32
VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system.
CVE-2023-20877
- EPSS 0.39%
- Veröffentlicht 12.05.2023 21:15:09
- Zuletzt bearbeitet 27.01.2025 18:15:32
VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation.
CVE-2023-20856
- EPSS 0.41%
- Veröffentlicht 01.02.2023 03:15:08
- Zuletzt bearbeitet 27.03.2025 15:15:42
VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of the authenticated victim user.
CVE-2022-31708
- EPSS 0.53%
- Veröffentlicht 16.12.2022 16:15:21
- Zuletzt bearbeitet 18.04.2025 14:15:18
vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.4.
CVE-2022-31707
- EPSS 0.37%
- Veröffentlicht 16.12.2022 16:15:21
- Zuletzt bearbeitet 18.04.2025 14:15:18
vRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2.
CVE-2022-31682
- EPSS 0.25%
- Veröffentlicht 11.10.2022 21:15:12
- Zuletzt bearbeitet 21.11.2024 07:05:07
VMware Aria Operations contains an arbitrary file read vulnerability. A malicious actor with administrative privileges may be able to read arbitrary files containing sensitive data.
CVE-2022-31675
- EPSS 0.13%
- Veröffentlicht 10.08.2022 20:15:45
- Zuletzt bearbeitet 21.11.2024 07:05:06
VMware vRealize Operations contains an authentication bypass vulnerability. An unauthenticated malicious actor with network access may be able to create a user with administrative privileges.
CVE-2022-31674
- EPSS 0.35%
- Veröffentlicht 10.08.2022 20:15:44
- Zuletzt bearbeitet 27.08.2025 19:15:35
VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can access log files that lead to information disclosure.
CVE-2022-31673
- EPSS 4.85%
- Veröffentlicht 10.08.2022 20:15:44
- Zuletzt bearbeitet 21.11.2024 07:05:05
VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can create and leak hex dumps, leading to information disclosure. Successful exploitation can lead to a remote code exec...