Vulnerabilities > Vmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-11-24 CVE-2020-4003 SQL Injection vulnerability in VMWare Sd-Wan Orchestrator
VMware SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 was found to be vulnerable to SQL-injection attacks allowing for potential information disclosure.
network
low complexity
vmware CWE-89
6.5
2020-11-24 CVE-2020-3984 SQL Injection vulnerability in VMWare Sd-Wan Orchestrator 3.3.2/3.4.0/3.4.4
The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3 and 3.4.x prior to 3.4.4 does not apply correct input validation which allows for SQL-injection.
network
low complexity
vmware CWE-89
6.5
2020-10-23 CVE-2020-3998 Unspecified vulnerability in VMWare Horizon Client
VMware Horizon Client for Windows (5.x prior to 5.5.0) contains an information disclosure vulnerability.
network
low complexity
vmware
6.5
2020-10-23 CVE-2020-3997 Cross-site Scripting vulnerability in VMWare Horizon
VMware Horizon Server (7.x prior to 7.10.3 or 7.13.0) contains a Cross Site Scripting (XSS) vulnerability.
network
low complexity
vmware CWE-79
5.4
2020-10-22 CVE-2020-3996 Unspecified vulnerability in VMWare Velero
Velero (prior to 1.4.3 and 1.5.2) in some instances doesn’t properly manage volume identifiers which may result in information leakage to unauthorized users.
local
low complexity
vmware
5.5
2020-10-20 CVE-2020-3995 Memory Leak vulnerability in VMWare products
In VMware ESXi (6.7 before ESXi670-201908101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x before 15.1.0), Fusion (11.x before 11.1.0), the VMCI host drivers used by VMware hypervisors contain a memory leak vulnerability.
network
high complexity
vmware CWE-401
5.3
2020-10-20 CVE-2020-3993 Unspecified vulnerability in VMWare Cloud Foundation and Nsx-T Data Center
VMware NSX-T (3.x before 3.0.2, 2.5.x before 2.5.2.2.0) contains a security vulnerability that exists in the way it allows a KVM host to download and install packages from NSX manager.
network
high complexity
vmware
5.9
2020-10-20 CVE-2020-3981 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in VMWare products
VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds read vulnerability due to a time-of-check time-of-use issue in ACPI device.
network
high complexity
vmware CWE-367
5.8
2020-09-22 CVE-2020-3977 Missing Authentication for Critical Function vulnerability in VMWare Horizon Daas 7.0.0/8.0.0/8.0.1
VMware Horizon DaaS (7.x and 8.x before 8.0.1 Update 1) contains a broken authentication vulnerability due to a flaw in the way it handled the first factor authentication.
network
low complexity
vmware CWE-306
6.5
2020-09-19 CVE-2020-5421 In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
network
high complexity
vmware oracle netapp
6.5