Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-31708: VMSA-2022-0034

vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.4.

CVE
#vulnerability#vmware#zero_day

Advisory ID: VMSA-2022-0034

CVSSv3 Range: 4.4-7.2

Issue Date: 2022-12-15

Updated On: 2022-12-15 (Initial Advisory)

CVE(s): CVE-2022-31707, CVE-2022-31708

Synopsis: VMware vRealize Operations (vROps) updates address privilege escalation vulnerabilities (CVE-2022-31707, CVE-2022-31708)

****1. Impacted Products****

  • VMware vRealize Operations (vROps)

****2. Introduction****

Multiple vulnerabilities in VMware vRealize Operations (vROps) were privately reported to VMware. Patches and updates are available to remediate these vulnerabilities in affected VMware products.

****3a. VMware vRealize Operations (vROps) privilege escalation vulnerability (CVE-2022-31707)****

vRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2.

A malicious actor with administrative privileges in the vROps application can gain root access to the underlying operating system.

To remediate CVE-2022-31707 apply the fixes listed in the ‘Fixed Version’ column of the ‘Response Matrix’ below.

VMware would like to thank Anonymous working with Trend Micro Zero Day Initiative, and thiscodecc of MoyunSec TopBreaker Labs and Bing Liu of MoyunSec for independently reporting this issue to us.

****3b. VMware vRealize Operations (vROps) contains an access control vulnerability (CVE-2022-31708)****

vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.4.

A malicious actor with admin privileges in the vROps application can read sensitive information from the underlying operating system.

To remediate CVE-2022-31708 apply the updates listed in the ‘Fixed Version’ column of the ‘Response Matrix’ below.

VMware would like to thank Anonymous working with Trend Micro Zero Day Initiative, and thiscodecc of MoyunSec TopBreaker Labs and Bing Liu of MoyunSec for independently reporting this issue to us.

Product

Version

Running On

CVE Identifier

CVSSv3

Severity

Fixed Version

Workarounds

Additional Documentation

VMware vRealize Operations (vROps)

8.10

Any

CVE-2022-31707, CVE-2022-31708

4.4, 7.2

important

8.10.1

N/A

N/A

VMware vRealize Operations (vROps)

8.6.x

Any

CVE-2022-31707, CVE-2022-31708

4.4, 7.2

important

KB90232

N/A

N/A

****4. References****

****5. Change Log****

2022-12-15 VMSA-2022-0034

Initial security advisory.

****6. Contact****

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907