QID 377932
Date Published: 2023-01-25
QID 377932: VMware vRealize Log Insight Multiple Security Vulnerabilities (VMSA-2023-0001)
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution. (CVE-2022-31706)
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.(CVE-2022-31704)
vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrusted data which could result in a denial of service.(CVE-2022-31710)
VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and application information without authentication. (CVE-2022-31711)
Affected Versions:
VMware vRealize Log Insight 8.x prior to 8.10.2.
Note: QID is kept potential due to the workaround. KB90635
Note : QID does not check for VMware Cloud Foundation
QID Detection Logic(Authenticated):
This QID checks for vulnerable versions of VMware vRealize Log Insight Automation by fetching the version from /opt/vmware/etc/appliance-manifest.xml.
Successful exploitation of the vulnerability may allow remote code execution and complete system compromise.
Workaround:
Please refer to KB90635 for information regarding workaround.
- VMSA-2023-0001 -
www.vmware.com/security/advisories/VMSA-2023-0001.html
CVEs related to QID 377932
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMSA-2023-0001 |
|