CVE-2022-31704: A critical broken access control vulnerability that could allow an unauthenticated malicious actor to perform RCE.<\/li>\n<\/ul>\n\n\n\nThe vulnerabilities affect all versions of the VMware vRealize Log Insight tool before v8.10.2. This vulnerability (CVE-2022-31706) allows an unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution. The (CVE-2022-31704) vulnerability allows an unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.<\/p>\n\n\n\n
Users and administrators of affected product versions are advised to update to the latest version immediately. For those that deployed this tool on a VMware Cloud Foundation environment (v4.x and v3.x), users and administrators are advised to upgrade their cloud environment to v4.4.1 first before updating the VMware vRealize log analysis tool.<\/p>\n","protected":false},"excerpt":{"rendered":"
Multiple vulnerabilities affecting VMware vRealize log analysis tool (known as VMware Aria Operations for Logs) were disclosed privately to VMware who in-turn has issued updates and workarounds to address these…<\/p>\n","protected":false},"author":1,"featured_media":12968,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25,13,28,16,18],"tags":[193,433,449,526,544,591,619,1253],"yoast_head":"\n
Multiple Vulnerabilities in VMware vRealize Log Analysis Tool<\/title>\n\n\n\n\n\n\n\n\n\n\n\n\n\n\t\n\t\n\t\n\n\n\n\n\n\t\n\t\n\t\n