VMware

Cloud Foundation

131 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 30.08.2021 18:15:08
  • Zuletzt bearbeitet 21.11.2024 05:49:27

The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery att...

  • EPSS 0.24%
  • Veröffentlicht 13.07.2021 19:15:09
  • Zuletzt bearbeitet 31.10.2025 11:44:38

SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a specially crafted request.

  • EPSS 0.4%
  • Veröffentlicht 13.07.2021 19:15:09
  • Zuletzt bearbeitet 31.10.2025 11:44:38

OpenSLP as used in ESXi has a denial-of-service vulnerability due a heap out-of-bounds read issue. A malicious actor with network access to port 427 on ESXi may be able to trigger a heap out-of-bounds read in OpenSLP service resulting in a denial-of-...

Warnung Exploit
  • EPSS 94.41%
  • Veröffentlicht 26.05.2021 15:15:07
  • Zuletzt bearbeitet 30.10.2025 20:05:29

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exp...

  • EPSS 1.49%
  • Veröffentlicht 26.05.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 05:49:22

The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-ins. A malicious actor with network acce...

Warnung Exploit
  • EPSS 94.42%
  • Veröffentlicht 31.03.2021 18:15:14
  • Zuletzt bearbeitet 30.10.2025 20:06:02

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrati...

Exploit
  • EPSS 83.18%
  • Veröffentlicht 31.03.2021 18:15:14
  • Zuletzt bearbeitet 21.11.2024 05:49:22

Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the un...

Exploit
  • EPSS 46.87%
  • Veröffentlicht 24.02.2021 17:15:16
  • Zuletzt bearbeitet 21.11.2024 05:49:21

OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427...

Warnung Exploit
  • EPSS 93.8%
  • Veröffentlicht 24.02.2021 17:15:15
  • Zuletzt bearbeitet 30.10.2025 20:06:27

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operatin...

Warnung
  • EPSS 90.34%
  • Veröffentlicht 24.02.2021 17:15:15
  • Zuletzt bearbeitet 30.10.2025 20:06:18

The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request ...