ZeroHour

CVE-2022-31704

CVSS 3.1
9.8 critical
EPSS
81%p100
Published
()
Modified
Description

The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in remote code execution.

Vendors
vmware
Products
vrealize log insight
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news