QID 730592

Date Published: 2022-08-10

QID 730592: VMware vRealize Operations Multiple Vulnerabilities (VMSA-2022-0022)

VMware vRealize Operations delivers self-driving IT operations management for private, hybrid, and multi-cloud environments in a unified, AI-powered platform.

Affected Versions(s):
VMware vRealize Operations Manager v8.x prior to 8.6.4

QID Detection Logic
This QID sends the GET request to ui/login.action and checks for vulnerable version.

Successful exploitation of these vulnerabilities may allow an unauthenticated attacker to bypass authentication and leak sensitive information or execute arbitrary code on the target system.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    The vendor has released updates to resolve this issue. Refer to VMSA-2022-0022 to obtain additional details.

    CVEs related to QID 730592

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2022-0022 URL Logo www.vmware.com/security/advisories/VMSA-2022-0022.html