3. XML External Entity (XXE) Vulnerability (CVE-2023-20855)
VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.8.
customerconnect.vmware.com/en/downloads/details?downloadGroup=VROVA-8111&productId=1399&rPId=101376
customerconnect.vmware.com/en/downloads/info/slug/infrastructure_operations_management/vmware_vrealize_automation/8_11
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-20855
docs.vmware.com/en/vRealize-Automation/services/rn/vrealize-automation-release-notes/index.html
docs.vmware.com/en/vRealize-Orchestrator/8.11.1/rn/vmware-vrealize-orchestrator-8111-release-notes/index.html
kb.vmware.com/s/article/90926
www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H