QID 376225

Date Published: 2022-01-06

QID 376225: VMware vRealize Orchestrator and VMware vRealize Automation Sensitive Information Disclosure Vulnerability (VMSA-2021-0023)

VMware vRealize Orchestrator is a modern workflow automation platform that simplifies and automates complex data center infrastructure tasks for increased extensibility and agility.

Affected Versions:
VMware vRealize Orchestrator 8.x up to 8.5

VMware vRealize Automation is part of the VMware vRealize Suite. Also referred to as vRA, it allows you to create and manage your private cloud without the need for complex manual processes. It's an automation tool for the private cloud.

Affected Versions:
VMware vRealize Automation 8.x up to 8.5

QID Detection Logic:(Authenticated)
It reads /opt/vmware/etc/appliance-manifest.xml file to check the vulnerable version of the product.

On successful exploitation an attacker can be able to redirect victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    The vendor has released patches which can be found VMSA-2021-0023

    CVEs related to QID 376225

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2021-0023 URL Logo www.vmware.com/security/advisories/VMSA-2021-0023.html