QID 730717

Date Published: 2023-02-01

QID 730717: VMware vRealize Log Insight Multiple Security Vulnerabilities (VMSA-2023-0001)

The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution. (CVE-2022-31706)
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.(CVE-2022-31704)
vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrusted data which could result in a denial of service.(CVE-2022-31710)
VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and application information without authentication. (CVE-2022-31711)

Affected Versions:
VMware vRealize Log Insight 8.x prior to 8.10.2.

QID Detection Logic(Unauthenticated):
This QID checks for vulnerable instances of VMware vRealize Log Insight Automation by sending a crafted payload to the webserver.

Successful exploitation of the vulnerability may allow remote code execution and complete system compromise.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to upgrade to VMware vRealize Log Insight version 8.10.2 or later. For more information please refer to VMSA-2023-0001

    CVEs related to QID 730717

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2023-0001 URL Logo www.vmware.com/security/advisories/VMSA-2023-0001.html