VMware Security Update – 20 April 2023

VMware has released a security update to fix multiple vulnerabilities across VMware Aria Operations for Logs (formerly vRealize Log Insight).

The addressed vulnerabilities could allow the remote attacker to gain access to the affected appliances via log deserialization and command injection vulnerabilities.

1. VMware Aria Operations for Logs Deserialization Vulnerability (CVE-2023- 20864):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access

2. VMware Aria Operations for Logs Command Injection Vulnerability (CVE-2023- 20865):

  • CVSS: 7.2
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities
  • CVE-2023-20864
  • CVE-2023-20865
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

VMware Security Advisory

References