Vmware Vrealize Operations vulnerabilities

18 known vulnerabilities affecting vmware/vrealize_operations.

Total CVEs
18
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH10MEDIUM5LOW1

Vulnerabilities

Page 1 of 1
CVE-2023-20878HIGHCVSS 7.2v8.6.0v8.10.02023-05-12
CVE-2023-20878 [HIGH] CWE-502 CVE-2023-20878: VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrati VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system.
nvd
CVE-2023-20877HIGHCVSS 8.8v8.6.0v8.10.02023-05-12
CVE-2023-20877 [HIGH] CWE-863 CVE-2023-20877: VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious use VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escalation.
nvd
CVE-2023-20879MEDIUMCVSS 6.7v8.6.0v8.10.02023-05-12
CVE-2023-20879 [MEDIUM] CVE-2023-20879: VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with a VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privileges in the Aria Operations application can gain root access to the underlying operating system.
nvd
CVE-2023-20856HIGHCVSS 8.8≥ 8.6.0, ≤ 8.6.42023-02-01
CVE-2023-20856 [HIGH] CWE-352 CVE-2023-20856: VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could exec VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of the authenticated victim user.
nvd
CVE-2022-31707HIGHCVSS 7.2≥ 8.6.0, < 8.6.4.20823815v8.10.02022-12-16
CVE-2022-31707 [HIGH] CWE-269 CVE-2022-31707: vRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the vRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2.
nvd
CVE-2022-31708MEDIUMCVSS 4.9≥ 8.6.0, < 8.6.4.20823815v8.10.02022-12-16
CVE-2022-31708 [MEDIUM] CWE-284 CVE-2022-31708: vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.4.
nvd
CVE-2022-31682MEDIUMCVSS 4.9≥ 8.0, < 8.102022-10-11
CVE-2022-31682 [MEDIUM] CVE-2022-31682: VMware Aria Operations contains an arbitrary file read vulnerability. A malicious actor with adminis VMware Aria Operations contains an arbitrary file read vulnerability. A malicious actor with administrative privileges may be able to read arbitrary files containing sensitive data.
nvd
CVE-2022-31673HIGHCVSS 8.8≥ 8.0.0, < 8.6.42022-08-10
CVE-2022-31673 [HIGH] CVE-2022-31673: VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malici VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can create and leak hex dumps, leading to information disclosure. Successful exploitation can lead to a remote code execution.
nvd
CVE-2022-31672HIGHCVSS 7.2≥ 8.0.0, < 8.6.42022-08-10
CVE-2022-31672 [HIGH] CWE-269 CVE-2022-31672: VMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with adm VMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network access can escalate privileges to root.
nvd
CVE-2022-31675HIGHCVSS 7.5≥ 8.0.0, < 8.6.42022-08-10
CVE-2022-31675 [HIGH] CVE-2022-31675: VMware vRealize Operations contains an authentication bypass vulnerability. An unauthenticated malic VMware vRealize Operations contains an authentication bypass vulnerability. An unauthenticated malicious actor with network access may be able to create a user with administrative privileges.
nvd
CVE-2022-31674MEDIUMCVSS 4.3≥ 8.0.0, < 8.6.42022-08-10
CVE-2022-31674 [MEDIUM] CWE-532 CVE-2022-31674: VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malici VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can access log files that lead to information disclosure.
nvd
CVE-2021-22033LOWCVSS 2.7≥ 7.0.0, < 8.6.02021-10-13
CVE-2021-22033 [LOW] CWE-918 CVE-2021-22033: Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulner Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability.
nvd
CVE-2020-3943CRITICALCVSS 9.8≥ 6.6.0, < 6.6.1≥ 6.7.0, < 6.7.12020-02-19
CVE-2020-3943 [CRITICAL] CVE-2020-3943: vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX R vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX RMI service which is not securely configured. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to execute arbitrary code in vRealize Operations.
nvd
CVE-2020-3944HIGHCVSS 8.6≥ 6.6.0, < 6.6.1≥ 6.7.0, < 6.7.12020-02-19
CVE-2020-3944 [HIGH] CWE-287 CVE-2020-3944: vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) has an impro vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) has an improper trust store configuration leading to authentication bypass. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to bypass Adapter authentication.
nvd
CVE-2020-3945HIGHCVSS 7.5≥ 6.6.0, < 6.6.1≥ 6.7.0, < 6.7.12020-02-19
CVE-2020-3945 [HIGH] CVE-2020-3945: vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) contains an vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) contains an information disclosure vulnerability due to incorrect pairing implementation between the vRealize Operations for Horizon Adapter and Horizon View. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, m
nvd
CVE-2018-6978MEDIUMCVSS 6.7≥ 6.6.0, < 6.6.1.11286876≥ 6.7.0, < 6.7.0.11286837+1 more2018-12-18
CVE-2018-6978 [MEDIUM] CWE-732 CVE-2018-6978: vRealize Operations (7.x before 7.0.0.11287810, 6.7.x before 6.7.0.11286837 and 6.6.x before 6.6.1.1 vRealize Operations (7.x before 7.0.0.11287810, 6.7.x before 6.7.0.11286837 and 6.6.x before 6.6.1.11286876) contains a local privilege escalation vulnerability due to improper permissions of support scripts. Admin user of the vROps application with shell access may exploit this issue to elevate the privileges to root on a vROps machine. Note: the adm
nvd
CVE-2016-7457CRITICALCVSS 10.0v6.0.0v6.1.0+3 more2016-12-29
CVE-2016-7457 [CRITICAL] CWE-264 CVE-2016-7457: VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to gain pr VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to gain privileges, or halt and remove virtual machines, via unspecified vectors.
nvd
CVE-2016-7462HIGHCVSS 8.5v6.0.0v6.1.0+3 more2016-12-29
CVE-2016-7462 [HIGH] CWE-264 CVE-2016-7462: The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenti The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files or rename files via a crafted DiskFileItem in a relay-request payload that is mishandled during deserialization.
nvd