VMware

Cloud Foundation

132 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.14%
  • Veröffentlicht 04.01.2022 22:15:07
  • Zuletzt bearbeitet 21.11.2024 05:49:29

VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A malicious actor with access to a virtu...

  • EPSS 8.29%
  • Veröffentlicht 24.11.2021 17:15:07
  • Zuletzt bearbeitet 21.11.2024 05:49:21

The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.

  • EPSS 0.8%
  • Veröffentlicht 10.11.2021 18:15:08
  • Zuletzt bearbeitet 31.10.2025 11:44:38

The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative access to vCenter Server may exploit this issue to elevate privileges ...

  • EPSS 0.16%
  • Veröffentlicht 13.10.2021 16:15:07
  • Zuletzt bearbeitet 21.11.2024 05:49:28

Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability.

  • EPSS 0.27%
  • Veröffentlicht 13.10.2021 16:15:07
  • Zuletzt bearbeitet 21.11.2024 05:49:28

VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interactive analytics export function. An authenticated malicious actor with non-administrative privileges may be able to embed untrusted ...

  • EPSS 1.23%
  • Veröffentlicht 23.09.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 05:49:26

The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attacker may exploit this issue to execute malicious scripts by tricking a victim into clicking a malicious link.

  • EPSS 0.38%
  • Veröffentlicht 23.09.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 05:49:26

The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to port 9087 on vCenter Server may exploit this issue to delete non critical files.

  • EPSS 1.47%
  • Veröffentlicht 23.09.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 05:49:27

The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 5480 on vCenter Server may exploit this issue by sending a specially crafted jsonrpc message to create a denial...

  • EPSS 0.12%
  • Veröffentlicht 23.09.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 05:49:27

The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this issue may allow an attacker to create a denial-of-service condition on vCenter Server.

Exploit
  • EPSS 1%
  • Veröffentlicht 23.09.2021 13:15:07
  • Zuletzt bearbeitet 21.11.2024 05:49:26

The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticated local user with non-administrative privilege may exploit these issues to elevate their privileges t...