Vulnerabilities > Vmware > Cloud Foundation > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-09-27 CVE-2023-34043 Improper Privilege Management vulnerability in VMWare Aria Operations and Cloud Foundation
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
local
low complexity
vmware CWE-269
6.7
2023-05-30 CVE-2023-20884 Open Redirect vulnerability in VMWare products
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.
network
low complexity
vmware CWE-601
6.1
2023-05-12 CVE-2023-20879 Unspecified vulnerability in VMWare Cloud Foundation and Vrealize Operations
VMware Aria Operations contains a Local privilege escalation vulnerability.
local
low complexity
vmware
6.7
2023-05-12 CVE-2023-20880 Unspecified vulnerability in VMWare Aria Operations and Cloud Foundation
VMware Aria Operations contains a privilege escalation vulnerability.
local
low complexity
vmware
6.7
2022-12-14 CVE-2022-31701 Missing Authentication for Critical Function vulnerability in VMWare products
VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability.
network
low complexity
vmware CWE-306
5.3
2022-12-13 CVE-2022-31697 Cleartext Storage of Sensitive Information vulnerability in VMWare Vcenter Server 6.5/6.7/7.0
The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext.
local
low complexity
vmware CWE-312
5.5
2022-12-13 CVE-2022-31698 Unspecified vulnerability in VMWare Cloud Foundation and Vcenter Server
The vCenter Server contains a denial-of-service vulnerability in the content library service.
network
low complexity
vmware
5.3
2022-10-07 CVE-2022-31681 NULL Pointer Dereference vulnerability in VMWare Esxi
VMware ESXi contains a null-pointer deference vulnerability.
local
low complexity
vmware CWE-476
6.5
2022-04-13 CVE-2022-22959 Cross-Site Request Forgery (CSRF) vulnerability in VMWare products
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability.
network
low complexity
vmware CWE-352
4.3
2022-04-13 CVE-2022-22961 Information Exposure vulnerability in VMWare products
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information.
network
low complexity
vmware CWE-200
5.3