ZeroHour

CVE-2021-22022

CVSS 3.1
4.9 medium
EPSS
1%p65
Published
()
Modified
Description

The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor with administrative access to vRealize Operations Manager API can read any arbitrary file on server leading to information disclosure.

Vendors
vmware
Products
cloud foundation, vrealize operations manager, vrealize suite lifecycle manager
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

In the news