CVE-2022-31704
26.01.2023, 21:15
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in remote code execution.Enginsight
Vendor | Product | Version |
---|---|---|
vmware | vrealize_log_insight | 3.0 ≤ 𝑥 ≤ 4.8 |
vmware | vrealize_log_insight | 8.0.0 ≤ 𝑥 < 8.10.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References