|
196141
|
9.8 |
CRITICAL
Network
|
vmware
|
identity_manager workspace_one_access cloud_foundation vrealize_suite_lifecycle_manager
|
VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network…
|
CWE-287
Improper Authentication
|
CVE-2021-22002
|
2024-11-21 14:49 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196142
|
7.5 |
HIGH
Network
|
vmware
|
workspace_one_uem_console
|
VMware Workspace ONE UEM REST API contains a denial of service vulnerability. A malicious actor with access to /API/system/admins/session could cause an API denial of service due to improper rate lim…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2021-22029
|
2024-11-21 14:49 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196143
|
9.8 |
CRITICAL
Network
|
att
|
xmill
|
A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2021-21811
|
2024-11-21 14:49 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196144
|
5.4 |
MEDIUM
Network
|
vmware
|
vrealize_log_insight cloud_foundation
|
VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user input validation. An attacker with user privileges may be able to inject a mali…
|
CWE-79
Cross-site Scripting
|
CVE-2021-22021
|
2024-11-21 14:49 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196145
|
7.5 |
HIGH
Network
|
vmware
|
vrealize_suite_lifecycle_manager cloud_foundation vrealize_operations_manager
|
The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manage…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-22027
|
2024-11-21 14:49 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196146
|
7.5 |
HIGH
Network
|
vmware
|
vrealize_suite_lifecycle_manager cloud_foundation vrealize_operations_manager
|
The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manage…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-22026
|
2024-11-21 14:49 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196147
|
7.5 |
HIGH
Network
|
vmware
|
vrealize_suite_lifecycle_manager cloud_foundation vrealize_operations_manager
|
The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unauthenticated malicious actor with network access to …
|
CWE-287
Improper Authentication
|
CVE-2021-22025
|
2024-11-21 14:49 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196148
|
7.5 |
HIGH
Network
|
vmware
|
vrealize_suite_lifecycle_manager cloud_foundation vrealize_operations_manager
|
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2021-22024
|
2024-11-21 14:49 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196149
|
7.2 |
HIGH
Network
|
vmware
|
vrealize_suite_lifecycle_manager cloud_foundation vrealize_operations_manager
|
The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to vRealize Operations Manager API may be able to modi…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2021-22023
|
2024-11-21 14:49 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196150
|
4.9 |
MEDIUM
Network
|
vmware
|
vrealize_suite_lifecycle_manager cloud_foundation vrealize_operations_manager
|
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor with administrative access to vRealize Operations Manager API can read any arbi…
|
CWE-22
Path Traversal
|
CVE-2021-22022
|
2024-11-21 14:49 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|