VMware Security Updates 18 December 2022

VMware has released security updates to fix vulnerabilities in VMware vRealize Operations (vROps).

The severity of the addressed vulnerabilities could allow the remote authenticated attacker to gain privilege or obtain information from the affected products via sending specially-crafted requests.

VMware vRealize Operations (vROps) privilege escalation vulnerability (CVE- 2022-31707):

• CVSS: 7.2

• Attack Vector: Network

• Attack Complexity: low

• Privileges Required: High

• User Interaction: None

• Consequences: Gain Privilege

Vulnerabilities
  • CVE-2022-31707
  • CVE-2022-31708
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

VMware Security Advisory

References