VMware vRealize Log Insight 4.6.1

CPE Details

VMware vRealize Log Insight 4.6.1
4.6.1
2019-09-30
14h35 +00:00
2019-09-30
14h35 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:vmware:vrealize_log_insight:4.6.1:*:*:*:*:*:*:*

Informations

Vendor

vmware

Product

vrealize_log_insight

Version

4.6.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-31704 2023-01-25 00h00 +00:00 The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in remote code execution.
9.8
Critical
CVE-2022-31706 2023-01-25 00h00 +00:00 The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
9.8
Critical
CVE-2022-31710 2023-01-25 00h00 +00:00 vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrusted data which could result in a denial of service.
7.5
High
CVE-2022-31711 2023-01-25 00h00 +00:00 VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and application information without authentication.
5.3
Medium
CVE-2022-31703 2022-12-13 23h00 +00:00 The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
7.5
High
CVE-2022-31655 2022-07-12 18h44 +00:00 VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in alerts.
5.4
Medium
CVE-2022-31654 2022-07-12 18h43 +00:00 VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in configurations.
5.4
Medium
CVE-2021-22021 2021-08-30 16h06 +00:00 VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user input validation. An attacker with user privileges may be able to inject a malicious payload via the Log Insight UI which would be executed when the victim accesses the shared dashboard link.
5.4
Medium
CVE-2020-3953 2020-04-15 15h20 +00:00 Cross Site Scripting (XSS) vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.
4.8
Medium
CVE-2020-3954 2020-04-15 15h17 +00:00 Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.
6.1
Medium
CVE-2018-6980 2018-11-13 21h00 +00:00 VMware vRealize Log Insight (4.7.x before 4.7.1 and 4.6.x before 4.6.2) contains a vulnerability due to improper authorization in the user registration method. Successful exploitation of this issue may allow Admin users with view only permission to perform certain administrative functions which they are not allowed to perform.
7.2
High