imPC@ndo EN

Vulnerabilità VMware

956 CVE

CVE-2014-6271
Sfruttata Critica 9.8

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature …

apple mac_os_x · arista eos · canonical ubuntu_linux · checkpoint security_gateway · e altri 70
1.00EPSS
CVE-2021-22005
Ransomware Critica 9.8

The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.

vmware cloud_foundation · vmware vcenter_server
1.00EPSS
CVE-2021-21985
Ransomware Critica 9.8

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this …

vmware cloud_foundation · vmware vcenter_server
1.00EPSS
CVE-2022-22954
Ransomware Critica 9.8

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

vmware cloud_foundation · vmware identity_manager · vmware vrealize_automation · vmware vrealize_suite_lifecycle_manager · e altri 1
1.00EPSS
CVE-2014-7169
Sfruttata Critica 9.8

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as …

apple mac_os_x · arista eos · canonical ubuntu_linux · checkpoint security_gateway · e altri 70
1.00EPSS
CVE-2022-22963
Sfruttata Critica 9.8

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local r…

oracle banking_branch · oracle banking_cash_management · oracle banking_corporate_lending_process_management · oracle banking_credit_facilities_process_management · e altri 24
1.00EPSS
CVE-2022-22965
Sfruttata Critica 9.8

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot …

cisco cx_cloud_agent · oracle commerce_platform · oracle communications_cloud_native_core_automated_test_suite · oracle communications_cloud_native_core_binding_support_function · e altri 34
1.00EPSS
CVE-2021-21972
Ransomware Critica 9.8

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system t…

vmware cloud_foundation · vmware vcenter_server
1.00EPSS
CVE-2023-34048
Sfruttata Critica 9.8

vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.

vmware vcenter_server
0.99EPSS
CVE-2023-20887
Sfruttata Critica 9.8

Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.

vmware aria_operations_for_networks
0.98EPSS
CVE-2022-22947
Sfruttata Critica 10.0

In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could all…

oracle commerce_guided_search · oracle communications_cloud_native_core_binding_support_function · oracle communications_cloud_native_core_console · oracle communications_cloud_native_core_network_exposure_function · e altri 6
0.98EPSS
CVE-2021-22054
Sfruttata Alta 7.5

VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their req…

vmware workspace_one_uem_console
0.97EPSS
CVE-2019-5544
Ransomware Critica 9.8

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

fedoraproject fedora · openslp openslp · redhat enterprise_linux_desktop · redhat enterprise_linux_for_ibm_z_systems · e altri 12
0.97EPSS
CVE-2020-11651
Sfruttata Critica 9.8

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be us…

canonical ubuntu_linux · debian debian_linux · opensuse leap · saltstack salt · e altri 1
0.97EPSS
CVE-2018-1273
Ransomware Critica 9.8

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supp…

apache ignite · broadcom spring_data_commons · oracle financial_services_crime_and_compliance_management_studio · pivotal_software spring_data_rest · e altri 1
0.96EPSS
CVE-2020-5410
Sfruttata Alta 7.5

Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a…

vmware spring_cloud_config
0.96EPSS
CVE-2020-3952
Sfruttata Critica 9.8

Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.

vmware vcenter_server
0.90EPSS
CVE-2021-21973
Sfruttata Media 5.3

The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter…

vmware cloud_foundation · vmware vcenter_server
0.88EPSS
CVE-2018-6961
Sfruttata Alta 8.1

VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is disabled by default and should not be enabled on untrusted networks. VeloCloud by VMware will be removing thi…

vmware nsx_sd-wan_by_velocloud
0.86EPSS
CVE-2020-11652
Sfruttata Media 6.5

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users.

blackberry workspaces_server · canonical ubuntu_linux · debian debian_linux · opensuse leap · e altri 2
0.86EPSS
CVE-2020-3992
Ransomware Critica 9.8

OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-202010401-SG) has a use-after-free issue. A malicious actor residing in the management network who has access to port 427 on an ESXi machine…

vmware cloud_foundation · vmware esxi
0.83EPSS
CVE-2021-21975
Ransomware Alta 7.5

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credent…

vmware cloud_foundation · vmware vrealize_operations_manager · vmware vrealize_suite_lifecycle_manager
0.78EPSS
CVE-2023-29552
Sfruttata Alta 7.5

The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor.

netapp smi-s_provider · service_location_protocol_project service_location_protocol · suse linux_enterprise_server · suse manager_server · e altri 1
0.66EPSS
CVE-2024-38812
Sfruttata Critica 9.8

The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to …

vmware cloud_foundation · vmware vcenter_server
0.55EPSS
CVE-2021-22017
Sfruttata Media 5.3

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being acc…

vmware vcenter_server
0.49EPSS