Vulnerabilities > CVE-2023-20855 - XXE vulnerability in VMWare Vrealize Automation and Vrealize Orchestrator
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sensitive information or possible escalation of privileges.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 8 |