Description
VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 1.8 | Impact: 6.0Attack Vector: Network
Complexity: High
Privileges: Low
User Interaction: None
Scope: Changed
Confidentiality: High
Integrity: High
Availability: High
Affected Packages3 packages
🔴Vulnerability Details
2GHSAGHSA-x379-p5q2-7954: VMware Aria Operations for Logs contains an information disclosure vulnerability↗2025-01-30 ▶ CVEListVMware Aria Operations for Logs information disclosure vulnerability↗2025-01-30 ▶ 📋Vendor Advisories
2OracleOracle Oracle PeopleSoft Risk Matrix: File Processing (libssh2) — CVE-2020-22218↗2025-01-15 ▶ MicrosoftAn issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory.↗2023-08-08 ▶