Lucene search

K
zdiSina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam)ZDI-23-842
HistoryJun 08, 2023 - 12:00 a.m.

VMware Aria Operations for Networks exportPDF Code Injection Information Disclosure Vulnerability

2023-06-0800:00:00
Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam)
www.zerodayinitiative.com
11
vmware
aria operations
networks
exportpdf
code injection
information disclosure
vulnerability
remote attackers
sensitive information
authentication
flaw
validation
user-supplied string
javascript code
service account

0.488 Medium

EPSS

Percentile

97.5%

This vulnerability allows remote attackers to disclose sensitive information on affected installations of VMware Aria Operations for Networks. Authentication is required to exploit this vulnerability. The specific flaw exists within the exportPDF method. The issue results from the lack of proper validation of a user-supplied string before using it to execute JavaScript code. An attacker can leverage this vulnerability to disclose information in the context of the service account.

0.488 Medium

EPSS

Percentile

97.5%