CVE-2021-21991
- EPSS 0.03%
- Veröffentlicht 22.09.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 05:49:23
The vCenter Server contains a local privilege escalation vulnerability due to the way it handles session tokens. A malicious actor with non-administrative user access on vCenter Server host may exploit this issue to escalate privileges to Administrat...
CVE-2021-21992
- EPSS 0.32%
- Veröffentlicht 22.09.2021 19:15:09
- Zuletzt bearbeitet 21.11.2024 05:49:23
The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with non-administrative user access to the vCenter Server vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash) may...
CVE-2021-22002
- EPSS 0.46%
- Veröffentlicht 31.08.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:25
VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443 could tamper with host headers ...
CVE-2021-22003
- EPSS 0.42%
- Veröffentlicht 31.08.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:25
VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be pract...
CVE-2021-22021
- EPSS 0.24%
- Veröffentlicht 30.08.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:27
VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user input validation. An attacker with user privileges may be able to inject a malicious payload via the Log Insight UI which would be...
CVE-2021-22022
- EPSS 0.21%
- Veröffentlicht 30.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:27
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor with administrative access to vRealize Operations Manager API can read any arbitrary file on server leading to information disclos...
CVE-2021-22023
- EPSS 0.32%
- Veröffentlicht 30.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:27
The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to vRealize Operations Manager API may be able to modify other users information leading to an account ta...
CVE-2021-22024
- EPSS 0.27%
- Veröffentlicht 30.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:27
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read any log file resulting in sensitive infor...
CVE-2021-22025
- EPSS 0.19%
- Veröffentlicht 30.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:27
The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can add new nod...
CVE-2021-22026
- EPSS 0.25%
- Veröffentlicht 30.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:27
The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery att...