VMware Releases Security Update for vRealize Operations Product
Security update addresses two vulnerabilities in VMware vRealize Operations
Summary
Security update addresses two vulnerabilities in VMware vRealize Operations
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
VMware has released security updates to address two security vulnerabilities within VMware vRealize Operations. The first vulnerability CVE-2022-31707 has a CVSSv3 score of 7.2 and concerns privilege escalation, potentially allowing an attacker with administrative privileges in the vRealize application to gain root access to the underlying operating system. The second vulnerability CVE-2022-31708 has a CVSSv3 score of 4.4 and involves a broken access control, potentially allowing an attacker with administrative privileges in the vRealize application to read sensitive information from the underlying operating system.
Remediation advice
Affected organisations are encouraged to review VMware Security Advisory VMSA-2022-0034 and apply any relevant updates or workarounds.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 22 December 2022 12:05 pm