VMware Cloud Foundation 5.2

CPE Details

VMware Cloud Foundation 5.2
5.2
2024-09-04
18h00 +00:00
2024-09-04
18h00 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:vmware:cloud_foundation:5.2:*:*:*:*:*:*:*

Informations

Vendor

vmware

Product

cloud_foundation

Version

5.2

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2025-41231 2025-05-20 12h54 +00:00 VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be able to perform certain unauthorised actions and access limited sensitive information.
7.3
Haute
CVE-2025-22222 2025-01-30 15h32 +00:00 VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known.
7.7
Haute
CVE-2025-22221 2025-01-30 15h30 +00:00 VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action in the Agent Configuration.
5.2
Moyen
CVE-2025-22220 2025-01-30 15h28 +00:00 VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin user.
5.4
Moyen
CVE-2025-22219 2025-01-30 15h26 +00:00 VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary operations as admin user.
9
Critique
CVE-2025-22218 2025-01-30 14h23 +00:00 VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs
8.5
Haute
CVE-2024-38834 2024-11-26 11h56 +00:00 VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to cloud provider might be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.
6.5
Moyen
CVE-2024-38833 2024-11-26 11h54 +00:00 VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to email templates might inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.
6.8
Moyen
CVE-2024-38832 2024-11-26 11h51 +00:00 VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.
7.1
Haute
CVE-2024-38831 2024-11-26 11h50 +00:00 VMware Aria Operations contains a local privilege escalation vulnerability.  A malicious actor with local administrative privileges can insert malicious commands into the properties file to escalate privileges to  a root user on the appliance running VMware Aria Operations.
7.8
Haute
CVE-2024-38830 2024-11-26 11h49 +00:00 VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this vulnerability to escalate privileges to root user on the appliance running VMware Aria Operations.
7.8
Haute
CVE-2024-22235 2024-02-21 04h59 +00:00 VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
6.7
Moyen
CVE-2022-31701 2022-12-14 00h00 +00:00 VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3.
5.3
Moyen
CVE-2022-31697 2022-12-13 00h00 +00:00 The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext passwords used during that operation.
5.5
Moyen