Skip to main content

Vendor/product archive

vmware / vrealize_automation CVEs

Beta · best-effort

20 CVEs tagged to vmware / vrealize_automation8 Critical, 6 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2022-22954

Published Apr 11, 2022

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can tri…

CVSS 9.8 · Critical
evidence mentions
30
Buzz score
78.5
KEV listedPublic PoC observed

CVE-2018-6959

Published Apr 13, 2018

VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs. Exploitation of this issue may lead to the hijacking of a valid vRA user's…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-6958

Published Apr 13, 2018

VMware vRealize Automation (vRA) prior to 7.3.1 contains a vulnerability that may allow for a DOM-based cross-site scripting (XSS) attack. Exploitation of this issue may lead to t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7460

Published Dec 29, 2016

The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attackers to read arbitrary files or c…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-5336

Published Aug 31, 2016

VMware vRealize Automation 7.0.x before 7.1 allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-2344

Published Mar 16, 2016

Cross-site scripting (XSS) vulnerability in VMware vRealize Automation 6.x before 6.2.4 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspe…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1