Skip to main content

Vendor/product archive

vmware / vrealize_log_insight CVEs

Beta · best-effort

15 CVEs tagged to vmware / vrealize_log_insight2 Critical, 4 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2022-31711

Published Jan 26, 2023

VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and application information without authenti…

CVSS 5.3 · Medium
evidence mentions
10
Buzz score
43.5
Vendor/product tagsBeta · best-effort

CVE-2022-31710

Published Jan 26, 2023

vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrusted data which could result in…

CVSS 7.5 · High
evidence mentions
9
Buzz score
37.5
Vendor/product tagsBeta · best-effort

CVE-2022-31706

Published Jan 26, 2023

The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance whic…

CVSS 9.8 · Critical
evidence mentions
13
Buzz score
45.9
Vendor/product tagsBeta · best-effort

CVE-2022-31704

Published Jan 26, 2023

The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance…

CVSS 9.8 · Critical
evidence mentions
10
Buzz score
38.5
Vendor/product tagsBeta · best-effort

CVE-2022-31703

Published Dec 14, 2022

The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance whic…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-31655

Published Jul 12, 2022

VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in alerts.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31654

Published Jul 12, 2022

VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in configurations.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-3954

Published Apr 15, 2020

Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-3953

Published Apr 15, 2020

Cross Site Scripting (XSS) vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-6980

Published Nov 13, 2018

VMware vRealize Log Insight (4.7.x before 4.7.1 and 4.6.x before 4.6.2) contains a vulnerability due to improper authorization in the user registration method. Successful exploita…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5332

Published Aug 31, 2016

Directory traversal vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.6.0 allows remote attackers to read arbitrary files via unspecified vectors.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2082

Published Jul 3, 2016

Cross-site request forgery (CSRF) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to hijack the authentication of unspecified victims…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-2081

Published Jul 3, 2016

Cross-site scripting (XSS) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vec…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1