Vulnerabilities > Vmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-06-07 CVE-2022-31693 Unspecified vulnerability in VMWare Tools
VMware Tools for Windows (12.x.y prior to 12.1.5, 11.x.y and 10.x.y) contains a denial-of-service vulnerability in the VM3DMP driver.
local
low complexity
vmware
5.5
2023-05-30 CVE-2023-20884 Open Redirect vulnerability in VMWare products
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.
network
low complexity
vmware CWE-601
6.1
2023-05-26 CVE-2023-20868 Cross-site Scripting vulnerability in VMWare Nsx-T Data Center
NSX-T contains a reflected cross-site scripting vulnerability due to a lack of input validation.
network
low complexity
vmware CWE-79
6.1
2023-05-12 CVE-2023-20879 Unspecified vulnerability in VMWare Cloud Foundation and Vrealize Operations
VMware Aria Operations contains a Local privilege escalation vulnerability.
local
low complexity
vmware
6.7
2023-05-12 CVE-2023-20880 Unspecified vulnerability in VMWare Aria Operations and Cloud Foundation
VMware Aria Operations contains a privilege escalation vulnerability.
local
low complexity
vmware
6.7
2023-04-25 CVE-2023-20870 Out-of-bounds Read vulnerability in VMWare Fusion and Workstation
VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.
local
low complexity
vmware CWE-125
6.0
2023-04-19 CVE-2023-20862 Incomplete Cleanup vulnerability in multiple products
In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions.
network
low complexity
vmware netapp CWE-459
6.3
2023-04-13 CVE-2023-20863 Expression Language Injection vulnerability in VMWare Spring Framework
In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
network
low complexity
vmware CWE-917
6.5
2023-04-13 CVE-2023-20866 Unspecified vulnerability in VMWare Spring Session 3.0.0
In Spring Session version 3.0.0, the session id can be logged to the standard output stream.
network
low complexity
vmware
6.5
2023-03-23 CVE-2023-20861 Unspecified vulnerability in VMWare Spring Framework
In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
network
low complexity
vmware
6.5