Lucene search

K
zdiReno Robert of Trend Micro Zero Day InitiativeZDI-23-057
HistoryJan 18, 2023 - 12:00 a.m.

VMware vRealize Operations CaSA Improper Access Control Information Disclosure Vulnerability

2023-01-1800:00:00
Reno Robert of Trend Micro Zero Day Initiative
www.zerodayinitiative.com
16
vmware
vrealize operations
casa
improper access control
information disclosure
vulnerability
remote attackers
sensitive information
low-privileged code
configuration
lack of access control
root context

EPSS

0.001

Percentile

46.3%

This vulnerability allows remote attackers to disclose sensitive information on affected installations of VMware vRealize Operations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the configuration of CaSA. The issue results from the lack of proper access control. An attacker can leverage this vulnerability to disclose information in the context of root.

EPSS

0.001

Percentile

46.3%