<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – VMware vCenter Server</title>
  <link>https://cvedaily.com/pages/tags/vcenter.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/vcenter.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – VMware vCenter Server</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:00 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-22721 – VMware Aria Operations contains a privilege escalation vulnerability. A maliciou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22721</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22721</guid>
    <pubDate>Wed, 25 Feb 2026 21:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22721</strong></p>
  <p>VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria Operations. To remediate CVE-2026-22721, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found in  VMSA-2026-0001 https://support.broadcom.com/web/…</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22721">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41250 – VMware vCenter contains an SMTP header injection vulnerability. A malicious acto...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41250</guid>
    <pubDate>Mon, 29 Sep 2025 18:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41250</strong></p>
  <p>VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create scheduled tasks may be able to manipulate the notification emails sent for scheduled tasks.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41246 – VMware Tools for Windows contains an improper authorisation vulnerability due to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41246</guid>
    <pubDate>Mon, 29 Sep 2025 16:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41246</strong></p>
  <p>VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on a guest VM, who is already authenticated through vCenter or ESX may exploit this issue to access other guest VMs. Successful exploitation requires knowledge of credentials of the targeted VMs and vCenter or ESX.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-41241 – VMware vCenter contains a denial-of-service vulnerability. A malicious actor who...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41241</guid>
    <pubDate>Tue, 29 Jul 2025 13:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-41241</strong></p>
  <p>VMware vCenter contains a denial-of-service vulnerability. A malicious actor who is authenticated through vCenter and has permission to perform API calls for guest OS customisation may trigger this vulnerability to create a denial-of-service condition.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41241">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-37101 – A potential security vulnerability has been identified in HPE OneView for VMware...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-37101</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-37101</guid>
    <pubDate>Thu, 26 Jun 2025 06:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-37101</strong></p>
  <p>A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability could be exploited allowing an attacker with read only privilege to cause Vertical Privilege Escalation (operator can perform admin actions).</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-37101">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-41228 – VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41228</guid>
    <pubDate>Tue, 20 May 2025 15:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-41228</strong></p>
  <p>VMware ESXi and vCenter Server contain a reflected cross-site scripting vulnerability due to improper input validation. A malicious actor with network access to the login page of certain ESXi host or vCenter Server URL paths may exploit this issue to steal cookies or redirect to malicious websites.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-41226 – VMware ESXi contains a denial-of-service vulnerability that occurs when performi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41226</guid>
    <pubDate>Tue, 20 May 2025 15:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-41226</strong></p>
  <p>VMware ESXi contains a denial-of-service vulnerability that occurs when performing a guest operation. A malicious actor with guest operation privileges on a VM, who is already authenticated through vCenter Server or ESXi may trigger this issue to create a denial-of-service condition of guest VMs with VMware Tools running and guest operations enabled.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41225 – The vCenter Server contains an authenticated command-execution vulnerability. A ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41225</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41225</guid>
    <pubDate>Tue, 20 May 2025 15:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41225</strong></p>
  <p>The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to create or modify alarms and run script action may exploit this issue to run arbitrary commands on the vCenter Server.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41225">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2241 – A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2241</guid>
    <pubDate>Mon, 17 Mar 2025 17:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2241</strong></p>
  <p>A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can le…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-922</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2241">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-55064 – Multiple cross-site scripting (XSS) vulnerabilities in EasyVirt DC NetScope &lt;= 8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55064</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55064</guid>
    <pubDate>Mon, 03 Mar 2025 22:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-55064</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in EasyVirt DC NetScope <= 8.6.4 allow remote attackers to inject arbitrary JavaScript or HTML code via the (1) smtp_server, (2) smtp_account, (3) smtp_password, or (4) email_recipients parameter to /smtp/update; the (5) ntp or (6) dns parameter to /proxy/ntp/change; the (7) newVcenterAddress parameter to /process_new_vcenter.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55064">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-38813 – The vCenter Server contains a privilege escalation vulnerability. A malicious ac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38813</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38813</guid>
    <pubDate>Tue, 17 Sep 2024 18:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-38813</strong></p>
  <p>The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38813">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-38812 – The vCenter Server contains a heap-overflow vulnerability in the implementation ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38812</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38812</guid>
    <pubDate>Tue, 17 Sep 2024 18:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-38812</strong></p>
  <p>The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38812">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-37087 – The vCenter Server contains a denial-of-service vulnerability. A malicious actor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37087</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37087</guid>
    <pubDate>Tue, 25 Jun 2024 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-37087</strong></p>
  <p>The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37087">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-22385 – Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMwa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22385</guid>
    <pubDate>Tue, 25 Jun 2024 02:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-22385</strong></p>
  <p>Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read and write specific files.This issue affects Hitachi Storage Provider for VMware vCenter: from 3.1.0 before 3.7.4.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-37081 – The vCenter Server contains multiple local privilege escalation vulnerabilities ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37081</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37081</guid>
    <pubDate>Tue, 18 Jun 2024 06:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-37081</strong></p>
  <p>The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-556</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37081">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-37080 – vCenter Server contains a heap-overflow vulnerability in the implementation of t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37080</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37080</guid>
    <pubDate>Tue, 18 Jun 2024 06:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-37080</strong></p>
  <p>vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37080">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-37079 – vCenter Server contains a heap-overflow vulnerability in the implementation of t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37079</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37079</guid>
    <pubDate>Tue, 18 Jun 2024 06:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-37079</strong></p>
  <p>vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37079">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-22275 – The vCenter Server contains a partial file read vulnerability. A malicious actor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22275</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22275</guid>
    <pubDate>Tue, 21 May 2024 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-22275</strong></p>
  <p>The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22275">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22274 – The vCenter Server contains an authenticated remote code execution vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22274</guid>
    <pubDate>Tue, 21 May 2024 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22274</strong></p>
  <p>The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-21840 – Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMwar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21840</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21840</guid>
    <pubDate>Tue, 30 Jan 2024 03:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-21840</strong></p>
  <p>Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMware vCenter allows local users to read and write specific files.  This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.0.0 through 04.9.2.</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21840">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-43082 – Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmad...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43082</guid>
    <pubDate>Wed, 22 Nov 2023 17:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-43082</strong></p>
  <p>Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component. If a customer has a certificate signed by a third-party public Certificate Authority, the vCenter CA could be spoofed by an attacker who can obtain a CA-signed certificate.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-34056 – vCenter Server contains a partial information disclosure vulnerability. A malici...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34056</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34056</guid>
    <pubDate>Wed, 25 Oct 2023 18:17:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-34056</strong></p>
  <p>vCenter Server contains a partial information disclosure vulnerability. A malicious actor with non-administrative privileges to vCenter Server may leverage this issue to access unauthorized data.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-922</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34056">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-34048 – vCenter Server contains an out-of-bounds write vulnerability in the implementati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34048</guid>
    <pubDate>Wed, 25 Oct 2023 18:17:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-34048</strong></p>
  <p>vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-20896 – The VMware vCenter Server contains an out-of-bounds read vulnerability in the im...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20896</guid>
    <pubDate>Thu, 22 Jun 2023 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-20896</strong></p>
  <p>The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leading to denial-of-service of certain services (vmcad, vmdird, and vmafdd).</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20895 – The VMware vCenter Server contains a memory corruption vulnerability in the impl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20895</guid>
    <pubDate>Thu, 22 Jun 2023 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20895</strong></p>
  <p>The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger a memory corruption vulnerability which may bypass authentication.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20894 – The VMware vCenter Server contains an out-of-bounds write vulnerability in the i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20894</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20894</guid>
    <pubDate>Thu, 22 Jun 2023 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20894</strong></p>
  <p>The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bound write by sending a specially crafted packet leading to memory corruption.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20894">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20893 – The VMware vCenter Server contains a use-after-free vulnerability in the impleme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20893</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20893</guid>
    <pubDate>Thu, 22 Jun 2023 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20893</strong></p>
  <p>The VMware vCenter Server contains a use-after-free vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit this issue to execute arbitrary code on the underlying operating system that hosts vCenter Server.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20893">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20892 – The vCenter Server contains a heap overflow vulnerability due to the usage of un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20892</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20892</guid>
    <pubDate>Thu, 22 Jun 2023 12:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20892</strong></p>
  <p>The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may exploit heap-overflow vulnerability to execute arbitrary code on the underlying operating system that hosts vCenter Server.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20892">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-37935 – HPE OneView for VMware vCenter, in certain circumstances, may disclose the “HPE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-37935</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-37935</guid>
    <pubDate>Wed, 01 Mar 2023 08:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-37935</strong></p>
  <p>HPE OneView for VMware vCenter, in certain circumstances, may disclose the “HPE OneView” Username and Password.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-37935">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-4441 – Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMwa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-4441</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-4441</guid>
    <pubDate>Tue, 31 Jan 2023 02:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-4441</strong></p>
  <p>Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.9.0 before 04.9.1.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-4441">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-4041 – Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMwa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-4041</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-4041</guid>
    <pubDate>Tue, 31 Jan 2023 02:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-4041</strong></p>
  <p>Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation. This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.8.0 before 04.9.1.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-4041">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31698 – The vCenter Server contains a denial-of-service vulnerability in the content lib...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31698</guid>
    <pubDate>Tue, 13 Dec 2022 16:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31698</strong></p>
  <p>The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to trigger a denial-of-service condition by sending a specially crafted header.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31697 – The vCenter Server contains an information disclosure vulnerability due to the l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31697</guid>
    <pubDate>Tue, 13 Dec 2022 16:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31697</strong></p>
  <p>The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext passwords used during that operation.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31697">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-31680 – The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31680</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31680</guid>
    <pubDate>Fri, 07 Oct 2022 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-31680</strong></p>
  <p>The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter server may exploit this issue to execute arbitrary code on the underlying operating system that hosts the vCenter Server.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31680">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-2637 – Incorrect Privilege Assignment vulnerability in Hitachi Hitachi Storage Plug-in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2637</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2637</guid>
    <pubDate>Thu, 06 Oct 2022 18:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-2637</strong></p>
  <p>Incorrect Privilege Assignment vulnerability in Hitachi Hitachi Storage Plug-in for VMware vCenter allows remote authenticated users to cause privilege escalation.This issue affects Hitachi Storage Plug-in for VMware vCenter: from 04.8.0 before 04.9.0.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2637">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-22982 – The vCenter Server contains a server-side request forgery (SSRF) vulnerability. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22982</guid>
    <pubDate>Wed, 13 Jul 2022 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-22982</strong></p>
  <p>The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on the vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-22948 – The vCenter Server contains an information disclosure vulnerability due to impro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22948</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22948</guid>
    <pubDate>Tue, 29 Mar 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-22948</strong></p>
  <p>The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22948">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-22049 – The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forger...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22049</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22049</guid>
    <pubDate>Wed, 24 Nov 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-22049</strong></p>
  <p>The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22049">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21980 – The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21980</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21980</guid>
    <pubDate>Wed, 24 Nov 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21980</strong></p>
  <p>The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21980">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22048 – The vCenter Server contains a privilege escalation vulnerability in the IWA (Int...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22048</guid>
    <pubDate>Wed, 10 Nov 2021 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22048</strong></p>
  <p>The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative access to vCenter Server may exploit this issue to elevate privileges to a higher privileged group.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-22020 – The vCenter Server contains a denial-of-service vulnerability in the Analytics s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22020</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22020</guid>
    <pubDate>Thu, 23 Sep 2021 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-22020</strong></p>
  <p>The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this issue may allow an attacker to create a denial-of-service condition on vCenter Server.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22020">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22019 – The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22019</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22019</guid>
    <pubDate>Thu, 23 Sep 2021 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22019</strong></p>
  <p>The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 5480 on vCenter Server may exploit this issue by sending a specially crafted jsonrpc message to create a denial of service condition.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22019">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-22018 – The vCenter Server contains an arbitrary file deletion vulnerability in a VMware...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22018</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22018</guid>
    <pubDate>Thu, 23 Sep 2021 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-22018</strong></p>
  <p>The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to port 9087 on vCenter Server may exploit this issue to delete non critical files.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22018">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-22017 – Rhttproxy as used in vCenter Server contains a vulnerability due to improper imp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22017</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22017</guid>
    <pubDate>Thu, 23 Sep 2021 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-22017</strong></p>
  <p>Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22017">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-22016 – The vCenter Server contains a reflected cross-site scripting vulnerability due t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22016</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22016</guid>
    <pubDate>Thu, 23 Sep 2021 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-22016</strong></p>
  <p>The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attacker may exploit this issue to execute malicious scripts by tricking a victim into clicking a malicious link.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22016">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22015 – The vCenter Server contains multiple local privilege escalation vulnerabilities ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22015</guid>
    <pubDate>Thu, 23 Sep 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22015</strong></p>
  <p>The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticated local user with non-administrative privilege may exploit these issues to elevate their privileges to root on vCenter Server Appliance.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-552</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22014 – The vCenter Server contains an authenticated code execution vulnerability in VAM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22014</guid>
    <pubDate>Thu, 23 Sep 2021 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22014</strong></p>
  <p>The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastructure). An authenticated VAMI user with network access to port 5480 on vCenter Server may exploit this issue to execute code on the underlying operating system that hosts vCenter Server.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22013 – The vCenter Server contains a file path traversal vulnerability leading to infor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22013</guid>
    <pubDate>Thu, 23 Sep 2021 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22013</strong></p>
  <p>The vCenter Server contains a file path traversal vulnerability leading to information disclosure in the appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22012 – The vCenter Server contains an information disclosure vulnerability due to an un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22012</guid>
    <pubDate>Thu, 23 Sep 2021 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22012</strong></p>
  <p>The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-22011 – vCenter Server contains an unauthenticated API endpoint vulnerability in vCenter...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22011</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22011</guid>
    <pubDate>Thu, 23 Sep 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-22011</strong></p>
  <p>vCenter Server contains an unauthenticated API endpoint vulnerability in vCenter Server Content Library. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to perform unauthenticated VM network setting manipulation.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22011">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22010 – The vCenter Server contains a denial-of-service vulnerability in VPXD service. A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22010</guid>
    <pubDate>Thu, 23 Sep 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22010</strong></p>
  <p>The vCenter Server contains a denial-of-service vulnerability in VPXD service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to create a denial of service condition due to excessive memory consumption by VPXD service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22009 – The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22009</guid>
    <pubDate>Thu, 23 Sep 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22009</strong></p>
  <p>The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit these issues to create a denial of service condition due to excessive memory consumption by VAPI service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22008 – The vCenter Server contains an information disclosure vulnerability in VAPI (vCe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22008</guid>
    <pubDate>Thu, 23 Sep 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22008</strong></p>
  <p>The vCenter Server contains an information disclosure vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by sending a specially crafted json-rpc message to gain access to sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-22007 – The vCenter Server contains a local information disclosure vulnerability in the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22007</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22007</guid>
    <pubDate>Thu, 23 Sep 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-22007</strong></p>
  <p>The vCenter Server contains a local information disclosure vulnerability in the Analytics service. An authenticated user with non-administrative privilege may exploit this issue to gain access to sensitive information.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22007">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22006 – The vCenter Server contains a reverse proxy bypass vulnerability due to the way ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22006</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22006</guid>
    <pubDate>Thu, 23 Sep 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22006</strong></p>
  <p>The vCenter Server contains a reverse proxy bypass vulnerability due to the way the endpoints handle the URI. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to access restricted endpoints.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22006">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-22005 – The vCenter Server contains an arbitrary file upload vulnerability in the Analyt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22005</guid>
    <pubDate>Thu, 23 Sep 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-22005</strong></p>
  <p>The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21993 – The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21993</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21993</guid>
    <pubDate>Thu, 23 Sep 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21993</strong></p>
  <p>The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in vCenter Server Content Library. An authorised user with access to content library may exploit this issue by sending a POST request to vCenter Server leading to information disclosure.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21993">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21992 – The vCenter Server contains a denial-of-service vulnerability due to improper XM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21992</guid>
    <pubDate>Wed, 22 Sep 2021 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21992</strong></p>
  <p>The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with non-administrative user access to the vCenter Server vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash) may exploit this issue to create a denial-of-service condition on the vCenter Server host.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21991 – The vCenter Server contains a local privilege escalation vulnerability due to th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21991</guid>
    <pubDate>Wed, 22 Sep 2021 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21991</strong></p>
  <p>The vCenter Server contains a local privilege escalation vulnerability due to the way it handles session tokens. A malicious actor with non-administrative user access on vCenter Server host may exploit this issue to escalate privileges to Administrator on the vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash).</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-26584 – A security vulnerability in HPE OneView for VMware vCenter (OV4VC) could be expl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26584</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26584</guid>
    <pubDate>Thu, 03 Jun 2021 11:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-26584</strong></p>
  <p>A security vulnerability in HPE OneView for VMware vCenter (OV4VC) could be exploited remotely to allow Cross-Site Scripting. HPE has released the following software update to resolve the vulnerability in HPE OneView for VMware vCenter (OV4VC).</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26584">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21986 – The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21986</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21986</guid>
    <pubDate>Wed, 26 May 2021 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21986</strong></p>
  <p>The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-ins. A malicious actor with network access to port 443 on vCenter Server may perform actions allowed by the impacted plug-ins without authentication.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21986">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21985 – The vSphere Client (HTML5) contains a remote code execution vulnerability due to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21985</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21985</guid>
    <pubDate>Wed, 26 May 2021 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21985</strong></p>
  <p>The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21985">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-26987 – Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26987</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26987</guid>
    <pubDate>Mon, 15 Mar 2021 22:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-26987</strong></p>
  <p>Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploited could lead to Remote Code Execution. All versions of Element Plug-in for vCenter Server, Management Services versions prior to 2.17.56 and Management Node versions through 12.2 contain vulnerable versions of SpringB…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26987">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-28972 – In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsphere, and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-28972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-28972</guid>
    <pubDate>Sat, 27 Feb 2021 05:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-28972</strong></p>
  <p>In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsphere, and esxi servers (in the vmware.py files) does not always validate the SSL/TLS certificate.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28972">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21973 – The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21973</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21973</guid>
    <pubDate>Wed, 24 Feb 2021 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21973</strong></p>
  <p>The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 befor…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21973">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21972 – The vSphere Client (HTML5) contains a remote code execution vulnerability in a v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21972</guid>
    <pubDate>Wed, 24 Feb 2021 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21972</strong></p>
  <p>The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Clo…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21972">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3994 – VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session h...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3994</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3994</guid>
    <pubDate>Tue, 20 Oct 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3994</strong></p>
  <p>VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session hijack vulnerability in the vCenter Server Appliance Management Interface update function due to a lack of certificate validation. A malicious actor with network positioning between vCenter Server and an update repository may be able to perform a session hijack when the vCenter Server Appliance Management Interface is…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3994">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-3976 – VMware ESXi and vCenter Server contain a partial denial of service vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3976</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3976</guid>
    <pubDate>Fri, 21 Aug 2020 13:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-3976</strong></p>
  <p>VMware ESXi and vCenter Server contain a partial denial of service vulnerability in their respective authentication services. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3976">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-3952 – Under certain conditions, vmdir that ships with VMware vCenter Server, as part o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3952</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3952</guid>
    <pubDate>Fri, 10 Apr 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-3952</strong></p>
  <p>Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access controls.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3952">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-11992 – A security vulnerability in HPE OneView for VMware vCenter 9.5 could be exploite...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11992</guid>
    <pubDate>Wed, 18 Dec 2019 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-11992</strong></p>
  <p>A security vulnerability in HPE OneView for VMware vCenter 9.5 could be exploited remotely to allow Cross-Site Scripting.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-5538 – Sensitive information disclosure vulnerability resulting from a lack of certific...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5538</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5538</guid>
    <pubDate>Mon, 28 Oct 2019 16:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-5538</strong></p>
  <p>Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d) may allow a malicious actor to intercept sensitive data in transit over SCP. A malicious actor with man-in-the-middle positioning between vCenter Server Appliance and a backup…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5538">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-5537 – Sensitive information disclosure vulnerability resulting from a lack of certific...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5537</guid>
    <pubDate>Mon, 28 Oct 2019 16:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-5537</strong></p>
  <p>Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d) may allow a malicious actor to intercept sensitive data in transit over FTPS and HTTPS. A malicious actor with man-in-the-middle positioning between vCenter Server Appliance a…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5537">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-5531 – VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5531</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5531</guid>
    <pubDate>Wed, 18 Sep 2019 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-5531</strong></p>
  <p>VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 prior to ESXi600-201807103-SG) and VMware vCenter Server (6.7 prior to 6.7 U1b, 6.5 prior to 6.5 U2b, and 6.0 prior to 6.0 U3j) contain an information disclosure vulnerability in clients arising from insufficient session expiration. An attacker with physical access or an ability to mimic a websocket…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5531">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5534 – VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5534</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5534</guid>
    <pubDate>Wed, 18 Sep 2019 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5534</strong></p>
  <p>VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability where Virtual Machines deployed from an OVF could expose login information via the virtual machine's vAppConfig properties. A malicious actor with access to query the vAppConfig properties of a virtual machine deployed from an OVF may be able to view the cre…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5534">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5532 – VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5532</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5532</guid>
    <pubDate>Wed, 18 Sep 2019 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5532</strong></p>
  <p>VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability due to the logging of credentials in plain-text for virtual machines deployed through OVF. A malicious user with access to the log files containing vCenter OVF-properties of a virtual machine deployed from an OVF may be able to view the credentials used to d…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5532">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-6179 – An XML External Entity (XXE) processing vulnerability was reported in Lenovo XCl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-6179</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-6179</guid>
    <pubDate>Tue, 03 Sep 2019 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-6179</strong></p>
  <p>An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to version 2.5.0 , Lenovo XClarity Integrator (LXCI) for Microsoft System Center prior to version 7.7.0, and Lenovo XClarity Integrator (LXCI) for VMWare vCenter prior to version 6.1.0 that could allow information disclosure.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-6179">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-11242 – A man-in-the-middle vulnerability related to vCenter access was found in Cohesit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11242</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11242</guid>
    <pubDate>Fri, 12 Jul 2019 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-11242</strong></p>
  <p>A man-in-the-middle vulnerability related to vCenter access was found in Cohesity DataPlatform version 5.x and 6.x prior to 6.1.1c. Cohesity clusters did not verify TLS certificates presented by vCenter. This vulnerability could expose Cohesity user credentials configured to access vCenter.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11242">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5492 – Element Plug-in for vCenter Server versions prior to 4.2.3 may disclose sensitiv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5492</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5492</guid>
    <pubDate>Mon, 29 Apr 2019 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5492</strong></p>
  <p>Element Plug-in for vCenter Server versions prior to 4.2.3 may disclose sensitive account information to an unauthenticated attacker. NetApp HCI Compute Node versions prior to 1.4P2 bundle affected versions of Element Plug-in for vCenter Server.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5492">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3709 – IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3709</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3709</guid>
    <pubDate>Wed, 17 Apr 2019 14:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3709</strong></p>
  <p>IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while registering vCenter servers. A remote attacker can trick an admin user to potentially exploit this vulnerability to execute malicious HTML or JavaScript code in the context of the admin user.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3709">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1223 – Cloud Foundry Container Runtime (kubo-release), versions prior to 0.14.0, may le...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1223</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1223</guid>
    <pubDate>Mon, 17 Sep 2018 16:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1223</strong></p>
  <p>Cloud Foundry Container Runtime (kubo-release), versions prior to 0.14.0, may leak UAA and vCenter credentials to application logs. A malicious user with the ability to read the application logs could use these credentials to escalate privileges.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1223">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-5761 – A man-in-the-middle vulnerability related to vCenter access was found in Rubrik ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-5761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-5761</guid>
    <pubDate>Mon, 22 Jan 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-5761</strong></p>
  <p>A man-in-the-middle vulnerability related to vCenter access was found in Rubrik CDM 3.x and 4.x before 4.0.4-p2. This vulnerability might expose Rubrik user credentials configured to access vCenter as Rubrik clusters did not verify TLS certificates presented by vCenter.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-5761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4943 – VMware vCenter Server Appliance (vCSA) (6.5 before 6.5 U1d) contains a local pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4943</guid>
    <pubDate>Wed, 20 Dec 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4943</strong></p>
  <p>VMware vCenter Server Appliance (vCSA) (6.5 before 6.5 U1d) contains a local privilege escalation vulnerability via the 'showlog' plugin. Successful exploitation of this issue could result in a low privileged user gaining root level privileges over the appliance base OS.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4927 – VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4927</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4927</guid>
    <pubDate>Fri, 17 Nov 2017 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4927</strong></p>
  <p>VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle specially crafted LDAP network packets which may allow for remote denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-90</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4927">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-1378 – IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed une...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-1378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-1378</guid>
    <pubDate>Thu, 05 Oct 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-1378</strong></p>
  <p>IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed unencrypted login credentials to Vmware vCenter in the application trace output which could be obtained by a local user. IBM X-Force ID: 126875.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-1378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-4926 – VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4926</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4926</guid>
    <pubDate>Fri, 15 Sep 2017 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-4926</strong></p>
  <p>VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which will get executed when other VC users access the page.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4926">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-4923 – VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4923</guid>
    <pubDate>Tue, 01 Aug 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-4923</strong></p>
  <p>VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtained when using the vCenter Server Appliance file-based backup feature.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-4922 – VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4922</guid>
    <pubDate>Tue, 01 Aug 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-4922</strong></p>
  <p>VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the service startup script using world writable directories as temporary storage for critical information. Successful exploitation of this issue may allow unprivileged host users to access certain critical information when the service gets restarted.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4921 – VMware vCenter Server (6.5 prior to 6.5 U1) contains an insecure library loading...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4921</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4921</guid>
    <pubDate>Tue, 01 Aug 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4921</strong></p>
  <p>VMware vCenter Server (6.5 prior to 6.5 U1) contains an insecure library loading issue that occurs due to the use of LD_LIBRARY_PATH variable in an unsafe manner. Successful exploitation of this issue may allow unprivileged host users to load a shared library that may lead to privilege escalation.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4921">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-4919 – VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4919</guid>
    <pubDate>Fri, 28 Jul 2017 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-4919</strong></p>
  <p>VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to access Guest Operating Systems without the need to authenticate.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-4917 – VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4917</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4917</guid>
    <pubDate>Wed, 07 Jun 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-4917</strong></p>
  <p>VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4917">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-4057 – The "Plug-in for VMware vCenter" in VCE Vision Intelligent Operations before 2.6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-4057</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-4057</guid>
    <pubDate>Tue, 21 Feb 2017 19:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-4057</strong></p>
  <p>The "Plug-in for VMware vCenter" in VCE Vision Intelligent Operations before 2.6.5 sends a cleartext HTTP response upon a request for the Settings screen, which allows remote attackers to discover the admin user password by sniffing the network.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-4057">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-6110 – IBM Tivoli Storage Manager discloses unencrypted login credentials to Vmware vCe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-6110</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-6110</guid>
    <pubDate>Wed, 01 Feb 2017 22:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-6110</strong></p>
  <p>IBM Tivoli Storage Manager discloses unencrypted login credentials to Vmware vCenter that could be obtained by a local user.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-6110">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-7460 – The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-7460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-7460</guid>
    <pubDate>Thu, 29 Dec 2016 09:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-7460</strong></p>
  <p>The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-7459 – VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authentica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-7459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-7459</guid>
    <pubDate>Thu, 29 Dec 2016 09:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-7459</strong></p>
  <p>VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distributed Switch setup, or (3) Content Library XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-7458 – VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-7458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-7458</guid>
    <pubDate>Thu, 29 Dec 2016 09:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-7458</strong></p>
  <p>VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-7458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-5331 – CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5331</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5331</guid>
    <pubDate>Mon, 08 Aug 2016 01:59:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-5331</strong></p>
  <p>CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-93</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5331">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-6931 – Cross-site scripting (XSS) vulnerability in the vSphere Web Client in VMware vCe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-6931</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-6931</guid>
    <pubDate>Sun, 03 Jul 2016 01:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-6931</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in the vSphere Web Client in VMware vCenter Server 5.0 before U3g, 5.1 before U3d, and 5.5 before U2d allows remote attackers to inject arbitrary web script or HTML via a crafted URL.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-6931">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-2078 – Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-2078</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-2078</guid>
    <pubDate>Wed, 08 Jun 2016 14:59:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-2078</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5.1 before update 3d, 5.5 before update 3d, and 6.0 before update 2 on Windows allows remote attackers to inject arbitrary web script or HTML via the flashvars parameter.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-2078">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-2076 – Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-2076</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-2076</guid>
    <pubDate>Fri, 15 Apr 2016 14:59:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-2076</strong></p>
  <p>Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2.4.1 mishandles session content, which allows remote attackers to hijack sessions via a crafted web site.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-2076">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-6934 – Serialized-object interfaces in VMware vRealize Orchestrator 6.x, vCenter Orches...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-6934</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-6934</guid>
    <pubDate>Mon, 21 Dec 2015 03:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-6934</strong></p>
  <p>Serialized-object interfaces in VMware vRealize Orchestrator 6.x, vCenter Orchestrator 5.x, vRealize Operations 6.x, vCenter Operations 5.x, and vCenter Application Discovery Manager (vADM) 7.x allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-6934">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
