CVE-2023-20856

Severity
8.8HIGH
EPSS
0.5%
top 35.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 1

Description

VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of the authenticated victim user.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5vmware_vrealize_operations_(vrops)vRealize Operations Manager (vROps) 8.6.4
NVDvmware/vrealize_operations8.6.08.6.4

🔴Vulnerability Details

2
CVEList
CVE-2023-20856: VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability2023-02-01
GHSA
GHSA-6wr9-hw3v-g6rr: VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability2023-02-01

📋Vendor Advisories

1
VMware
VMware vRealize Operations (vROps) update addresses a CSRF bypass vulnerability (CVE-2023-20856)2023-01-31