VMware

Cloud Foundation

126 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.36%
  • Published 31.08.2021 22:15:08
  • Last modified 21.11.2024 05:49:25

VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be pract...

  • EPSS 0.24%
  • Published 30.08.2021 19:15:08
  • Last modified 21.11.2024 05:49:27

VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user input validation. An attacker with user privileges may be able to inject a malicious payload via the Log Insight UI which would be...

  • EPSS 0.21%
  • Published 30.08.2021 18:15:08
  • Last modified 21.11.2024 05:49:27

The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor with administrative access to vRealize Operations Manager API can read any arbitrary file on server leading to information disclos...

  • EPSS 0.32%
  • Published 30.08.2021 18:15:08
  • Last modified 21.11.2024 05:49:27

The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to vRealize Operations Manager API may be able to modify other users information leading to an account ta...

  • EPSS 0.27%
  • Published 30.08.2021 18:15:08
  • Last modified 21.11.2024 05:49:27

The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read any log file resulting in sensitive infor...

  • EPSS 0.19%
  • Published 30.08.2021 18:15:08
  • Last modified 21.11.2024 05:49:27

The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can add new nod...

  • EPSS 0.25%
  • Published 30.08.2021 18:15:08
  • Last modified 21.11.2024 05:49:27

The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery att...

  • EPSS 0.23%
  • Published 30.08.2021 18:15:08
  • Last modified 21.11.2024 05:49:27

The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery att...

Warning Exploit
  • EPSS 94.37%
  • Published 26.05.2021 15:15:07
  • Last modified 02.04.2025 16:53:15

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exp...

  • EPSS 0.98%
  • Published 26.05.2021 15:15:07
  • Last modified 21.11.2024 05:49:22

The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-ins. A malicious actor with network acce...