QID 730929

Date Published: 2023-10-05

QID 730929: VMware Aria Operations Local Privilege Escalation Vulnerability (VMSA-2023-0020)

VMWare has patched two vulnerabilities in its product VMware Aria Operations which is formerly known as vRealize Operations Manager.
VMware Aria Operations Local Privilege Escalation Vulnerability (CVE-2023-34043)
Affected Versions:
VMware Aria Operations versions 8.6.x, 8.10,8.12.x

QID Detection Logic
This QID sends the GET request to ui/login.action and checks for vulnerable version.

A malicious actor with administrative access to the local system can escalate privileges to 'root'.

  • CVSS V3 rated as High - 6.7 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Customers are advised to upgrade to VMware Aria Operations version. For more information please refer to VMSA-2023-0020

    CVEs related to QID 730929

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2023-0020 URL Logo www.vmware.com/security/advisories/VMSA-2023-0020.html