CVE-2023-20865
Severity
7.2HIGH
EPSS
0.7%
top 28.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 20
Latest updateOct 1
Description
VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9
Affected Packages3 packages
▶CVEListV5vmware_aria_operations_for_logs_(formerly_vrealize_log_insight)VMware Aria Operations for Logs (formerly vRealize Log Insight) prior to 8.12