Vulnerabilities > Vmware > Cloud Foundation > 4.1.0.1

DATE CVE VULNERABILITY TITLE RISK
2022-01-04 CVE-2021-22045 Out-of-bounds Write vulnerability in VMWare products
VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation.
local
high complexity
vmware CWE-787
7.8
2021-11-10 CVE-2021-22048 Unspecified vulnerability in VMWare Cloud Foundation and Vcenter Server
The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism.
network
low complexity
vmware
8.8
2021-10-13 CVE-2021-22033 Server-Side Request Forgery (SSRF) vulnerability in VMWare products
Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability.
network
low complexity
vmware CWE-918
2.7
2021-10-13 CVE-2021-22035 Injection vulnerability in VMWare products
VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interactive analytics export function.
network
low complexity
vmware CWE-74
4.3
2021-09-23 CVE-2021-22015 Files or Directories Accessible to External Parties vulnerability in VMWare Cloud Foundation and Vcenter Server
The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories.
local
low complexity
vmware CWE-552
7.8
2021-09-23 CVE-2021-22016 Cross-site Scripting vulnerability in VMWare Cloud Foundation and Vcenter Server
The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization.
network
low complexity
vmware CWE-79
6.1
2021-09-23 CVE-2021-22018 Unspecified vulnerability in VMWare Cloud Foundation and Vcenter Server
The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in.
network
low complexity
vmware
6.5
2021-09-23 CVE-2021-22019 Unspecified vulnerability in VMWare Cloud Foundation and Vcenter Server
The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service.
network
low complexity
vmware
7.5
2021-09-23 CVE-2021-22020 Unspecified vulnerability in VMWare Cloud Foundation and Vcenter Server
The vCenter Server contains a denial-of-service vulnerability in the Analytics service.
local
low complexity
vmware
5.5
2021-09-23 CVE-2021-21993 Server-Side Request Forgery (SSRF) vulnerability in VMWare Cloud Foundation and Vcenter Server
The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in vCenter Server Content Library.
network
low complexity
vmware CWE-918
6.5