📦 Vrealize Suite Lifecycle Manager

by Vmware

🔍 What is Vrealize Suite Lifecycle Manager?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-22972

CRITICAL CVSS 9.8 May 20, 2022

This authentication bypass vulnerability allows attackers with network access to the UI to gain administrative privileges without credentials. It affects VMware Workspace ONE Access, Identity Manager,...

CVE-2022-22954

CRITICAL CVSS 9.8 Apr 11, 2022

This vulnerability allows remote attackers to execute arbitrary code on VMware Workspace ONE Access and Identity Manager systems through server-side template injection. Attackers with network access c...

CVE-2021-22002

CRITICAL CVSS 9.8 Aug 31, 2021

This vulnerability allows attackers to bypass authentication and access sensitive configuration and diagnostic endpoints in VMware Workspace ONE Access and Identity Manager by manipulating host header...

CVE-2022-22957

HIGH CVSS 7.2 Apr 13, 2022

This vulnerability allows remote code execution in VMware Workspace ONE Access, Identity Manager, and vRealize Automation. An attacker with administrative access can exploit insecure deserialization v...

CVE-2022-22960

HIGH CVSS 7.8 Apr 13, 2022

This vulnerability allows a malicious actor with local access to VMware Workspace ONE Access, Identity Manager, or vRealize Automation systems to escalate privileges to root due to improper permission...

CVE-2021-22023

HIGH CVSS 7.2 Aug 30, 2021

This vulnerability allows an attacker with administrative API access to vRealize Operations Manager to modify other users' information, potentially leading to account takeover. It affects vRealize Ope...

CVE-2021-22025

HIGH CVSS 7.5 Aug 30, 2021

CVE-2021-22025 is a broken access control vulnerability in VMware vRealize Operations Manager API that allows unauthenticated attackers to add new nodes to existing vROps clusters. This affects vReali...

CVE-2021-22027

HIGH CVSS 7.5 Aug 30, 2021

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the vRealize Operations Manager API. Unauthenticated attackers with network access can exploit this to make the server send req...