Vulnerabilities > Vmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-11-30 CVE-2021-22095 Deserialization of Untrusted Data vulnerability in VMWare Spring Advanced Message Queuing Protocol
In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the message body, regardless of its size.
network
low complexity
vmware CWE-502
6.5
2021-11-08 CVE-2021-22051 Incorrect Authorization vulnerability in VMWare Spring Cloud Gateway
Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request on downstream services.
network
low complexity
vmware CWE-863
6.5
2021-10-28 CVE-2021-22047 Exposure of Resource to Wrong Sphere vulnerability in VMWare Spring Data Rest
In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that can potentially be exposed for unauthorized access depending on the Spring Security configuration.
network
low complexity
vmware CWE-668
5.3
2021-10-28 CVE-2021-22096 In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.
network
low complexity
vmware netapp oracle
4.3
2021-10-28 CVE-2021-22097 Deserialization of Untrusted Data vulnerability in VMWare Spring Advanced Message Queuing Protocol
In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a message with content type application/x-java-serialized-object.
network
low complexity
vmware CWE-502
6.5
2021-10-13 CVE-2021-22035 Injection vulnerability in VMWare products
VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interactive analytics export function.
network
low complexity
vmware CWE-74
4.3
2021-10-13 CVE-2021-22036 Information Exposure vulnerability in VMWare Vrealize Automation and Vrealize Orchestrator
VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling.
network
low complexity
vmware CWE-200
6.5
2021-09-23 CVE-2021-22016 Cross-site Scripting vulnerability in VMWare Cloud Foundation and Vcenter Server
The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization.
network
low complexity
vmware CWE-79
6.1
2021-09-23 CVE-2021-22017 Unspecified vulnerability in VMWare Vcenter Server 6.7
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.
network
low complexity
vmware
5.3
2021-09-23 CVE-2021-22018 Unspecified vulnerability in VMWare Cloud Foundation and Vcenter Server
The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in.
network
low complexity
vmware
6.5