VMware

Cloud Foundation

135 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.69%
  • Veröffentlicht 23.09.2021 12:15:07
  • Zuletzt bearbeitet 21.11.2024 05:49:25

The vCenter Server contains an information disclosure vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by sending a specially crafted json-rpc message to gain acce...

  • EPSS 1.47%
  • Veröffentlicht 23.09.2021 12:15:07
  • Zuletzt bearbeitet 21.11.2024 05:49:25

The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit these issues to create a denial of service condition due to excessiv...

  • EPSS 1.47%
  • Veröffentlicht 23.09.2021 12:15:07
  • Zuletzt bearbeitet 21.11.2024 05:49:26

The vCenter Server contains a denial-of-service vulnerability in VPXD service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to create a denial of service condition due to excessive memory consumption by V...

  • EPSS 0.82%
  • Veröffentlicht 23.09.2021 12:15:07
  • Zuletzt bearbeitet 21.11.2024 05:49:26

vCenter Server contains an unauthenticated API endpoint vulnerability in vCenter Server Content Library. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to perform unauthenticated VM network setting manipula...

  • EPSS 0.2%
  • Veröffentlicht 22.09.2021 19:15:09
  • Zuletzt bearbeitet 21.11.2024 05:49:23

The vCenter Server contains a local privilege escalation vulnerability due to the way it handles session tokens. A malicious actor with non-administrative user access on vCenter Server host may exploit this issue to escalate privileges to Administrat...

  • EPSS 0.93%
  • Veröffentlicht 22.09.2021 19:15:09
  • Zuletzt bearbeitet 21.11.2024 05:49:23

The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with non-administrative user access to the vCenter Server vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash) may...

  • EPSS 0.37%
  • Veröffentlicht 31.08.2021 22:15:08
  • Zuletzt bearbeitet 21.11.2024 05:49:25

VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443 could tamper with host headers ...

  • EPSS 0.27%
  • Veröffentlicht 31.08.2021 22:15:08
  • Zuletzt bearbeitet 21.11.2024 05:49:25

VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be pract...

  • EPSS 0.24%
  • Veröffentlicht 30.08.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 05:49:27

VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user input validation. An attacker with user privileges may be able to inject a malicious payload via the Log Insight UI which would be...

  • EPSS 0.21%
  • Veröffentlicht 30.08.2021 18:15:08
  • Zuletzt bearbeitet 21.11.2024 05:49:27

The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor with administrative access to vRealize Operations Manager API can read any arbitrary file on server leading to information disclos...