Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid ‘member’ role credentials may be able to perform a deserialization attack resulting in remote code execution.
[
{
"defaultStatus": "unaffected",
"product": "Aria Operations for Networks (Formerly vRealize Network Insight)",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "Aria Operations for Networks (Formerly vRealize Network Insight) 6.x"
}
]
}
]