ZeroHour

CVE-2021-22036

CVSS 3.1
6.5 medium
EPSS
<1%p58
Published
()
Modified
Description

VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. A malicious actor may be able to redirect victim to an attacker controlled domain due to improper path handling in vRealize Orchestrator leading to sensitive information disclosure.

Vendors
vmware
Products
vrealize automation, vrealize orchestrator
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.