VMware

Cloud Foundation

126 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.44%
  • Published 13.10.2021 16:15:07
  • Last modified 21.11.2024 05:49:28

VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interactive analytics export function. An authenticated malicious actor with non-administrative privileges may be able to embed untrusted ...

  • EPSS 0.55%
  • Published 23.09.2021 13:15:08
  • Last modified 21.11.2024 05:49:26

The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attacker may exploit this issue to execute malicious scripts by tricking a victim into clicking a malicious link.

  • EPSS 0.52%
  • Published 23.09.2021 13:15:08
  • Last modified 21.11.2024 05:49:26

The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to port 9087 on vCenter Server may exploit this issue to delete non critical files.

  • EPSS 1.07%
  • Published 23.09.2021 13:15:08
  • Last modified 21.11.2024 05:49:27

The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 5480 on vCenter Server may exploit this issue by sending a specially crafted jsonrpc message to create a denial...

  • EPSS 0.08%
  • Published 23.09.2021 13:15:08
  • Last modified 21.11.2024 05:49:27

The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this issue may allow an attacker to create a denial-of-service condition on vCenter Server.

Exploit
  • EPSS 2.27%
  • Published 23.09.2021 13:15:07
  • Last modified 21.11.2024 05:49:26

The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticated local user with non-administrative privilege may exploit these issues to elevate their privileges t...

  • EPSS 0.66%
  • Published 23.09.2021 12:15:08
  • Last modified 21.11.2024 05:49:26

The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information...

  • EPSS 0.73%
  • Published 23.09.2021 12:15:08
  • Last modified 21.11.2024 05:49:26

The vCenter Server contains a file path traversal vulnerability leading to information disclosure in the appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive ...

  • EPSS 1.62%
  • Published 23.09.2021 12:15:08
  • Last modified 21.11.2024 05:49:26

The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastructure). An authenticated VAMI user with network access to port 5480 on vCenter Server may exploit this issue to execute code on t...

  • EPSS 0.17%
  • Published 23.09.2021 12:15:07
  • Last modified 21.11.2024 05:49:24

The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in vCenter Server Content Library. An authorised user with access to content library may exploit this issue by sending a POST request t...