Lucene search

K
vmwareVMwareVMSA-2023-0001
HistoryJan 24, 2023 - 12:00 a.m.

VMware vRealize Log Insight latest updates address multiple security vulnerabilities (CVE-2022-31706, CVE-2022-31704, CVE-2022-31710, CVE-2022-31711)

2023-01-2400:00:00
www.vmware.com
72
vmware
vrealize log insight
security updates
directory traversal
broken access control
information disclosure

AI Score

7.2

Confidence

Low

EPSS

0.009

Percentile

83.1%

3a. VMware vRealize Log Insight Directory Traversal Vulnerability (CVE-2022-31706)

The vRealize Log Insight contains a Directory Traversal Vulnerability. VMware has evaluated the severity of this issue to be in the critical severity range with a maximum CVSSv3 base score of 9.8.

3b. VMware vRealize Log Insight broken access control Vulnerability (CVE-2022-31704)

The vRealize Log Insight contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the critical severity range with a maximum CVSSv3 base score of 9.8.

Acknowledgements

VMware would like to thank ZDI for reporting this vulnerability to us.

3d. VMware vRealize Log Insight contains an Information Disclosure Vulnerability (CVE-2022-31711)

vRealize Log Insight contains an Information Disclosure Vulnerability. VMware has evaluated the severity of this issue to be in the moderate severity range with a maximum CVSSv3 base score of 5.3.

AI Score

7.2

Confidence

Low

EPSS

0.009

Percentile

83.1%