Show filters
28 Total Results
Displaying 1-10 of 28
Sort by:
Attacker Value
Very High

CVE-2021-21975

Disclosure Date: March 31, 2021 (last updated June 05, 2021)
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
Attacker Value
Unknown

CVE-2017-4946

Disclosure Date: January 05, 2018 (last updated November 26, 2024)
The VMware V4H and V4PA desktop agents (6.x before 6.5.1) contain a privilege escalation vulnerability. Successful exploitation of this issue could result in a low privileged windows user escalating their privileges to SYSTEM.
1
Attacker Value
Very High

CVE-2021-21983

Disclosure Date: March 31, 2021 (last updated November 28, 2024)
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.
Attacker Value
Unknown

CVE-2023-20879

Disclosure Date: May 12, 2023 (last updated October 08, 2023)
VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privileges in the Aria Operations application can gain root access to the underlying operating system.
Attacker Value
Unknown

CVE-2023-20878

Disclosure Date: May 12, 2023 (last updated October 08, 2023)
VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system.
Attacker Value
Unknown

CVE-2023-20877

Disclosure Date: May 12, 2023 (last updated October 08, 2023)
VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation.
Attacker Value
Unknown

CVE-2023-20856

Disclosure Date: February 01, 2023 (last updated October 08, 2023)
VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of the authenticated victim user.
Attacker Value
Unknown

CVE-2022-31708

Disclosure Date: December 16, 2022 (last updated October 08, 2023)
vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.4.
Attacker Value
Unknown

CVE-2022-31707

Disclosure Date: December 16, 2022 (last updated October 08, 2023)
vRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2.
Attacker Value
Unknown

CVE-2022-31682

Disclosure Date: October 11, 2022 (last updated October 08, 2023)
VMware Aria Operations contains an arbitrary file read vulnerability. A malicious actor with administrative privileges may be able to read arbitrary files containing sensitive data.