CVE-2023-20855
published 2023-02-22CVE-2023-20855: VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator…
PriorityP350high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.26%
66.5th percentile
VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sensitive information or possible escalation of privileges.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vrealize_automation | >= 8.0 < 8.11.1 | 8.11.1 |
| vmware | vrealize_orchestrator | >= 8.0 < 8.11.1 | 8.11.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3hq4-5qpg-7776: VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability
ghsa_unreviewed·2023-02-22
CVE-2023-20855 [HIGH] CWE-611 GHSA-3hq4-5qpg-7776: VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability
VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sensitive information or possible escalation of privileges.
VMware
VMware vRealize Orchestrator update addresses an XML External Entity (XXE) vulnerability (CVE-2023-20855)
vendor_vmware·2023-02-21·CVSS 8.8
CVE-2023-20855 [HIGH] VMware vRealize Orchestrator update addresses an XML External Entity (XXE) vulnerability (CVE-2023-20855)
VMSA-2023-0005: VMware vRealize Orchestrator update addresses an XML External Entity (XXE) vulnerability (CVE-2023-20855)
VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.8.
CVEs: CVE-2023-20855
Affected products: VMware Aria, VMware Cloud Foundation, VMware vRealize
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-22
Published