VMware Security Update – 16 January 2024

VMware has released a security update to address a critical vulnerability across VMware Aria Automation (formerly vRealize Automation), and VMware Cloud Foundation (Aria Automation).

The addressed vulnerability could allow the authenticated attacker to gain unauthorized access to remote organizations and workflows.

VMware Aria Automation Missing Access Control Vulnerability (CVE-2023-34063):

  • CVSS: 9.9
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities

CVE-2023-34063

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

VMware Security Advisory

References