Vulnerabilities > Vmware > Vrealize Orchestrator

DATE CVE VULNERABILITY TITLE RISK
2023-02-22 CVE-2023-20855 XXE vulnerability in VMWare Vrealize Automation and Vrealize Orchestrator
VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability.
network
low complexity
vmware CWE-611
8.8
2021-10-13 CVE-2021-22036 Information Exposure vulnerability in VMWare Vrealize Automation and Vrealize Orchestrator
VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling.
network
vmware CWE-200
4.3
2015-12-21 CVE-2015-6934 Improper Input Validation vulnerability in VMWare Vcenter Orchestrator and Vrealize Orchestrator
Serialized-object interfaces in VMware vRealize Orchestrator 6.x, vCenter Orchestrator 5.x, vRealize Operations 6.x, vCenter Operations 5.x, and vCenter Application Discovery Manager (vADM) 7.x allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
network
low complexity
vmware CWE-20
7.5