Skip to main content

VMware Releases Security Update for vRealize Operations Product

Security update addresses two vulnerabilities in VMware vRealize Operations

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security update addresses two vulnerabilities in VMware vRealize Operations


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

VMware has released security updates to address two security vulnerabilities within VMware vRealize Operations. The first vulnerability CVE-2022-31707 has a CVSSv3 score of 7.2 and concerns privilege escalation, potentially allowing an attacker with administrative privileges in the vRealize application to gain root access to the underlying operating system. The second vulnerability CVE-2022-31708 has a CVSSv3 score of 4.4 and involves a broken access control, potentially allowing an attacker with administrative privileges in the vRealize application to read sensitive information from the underlying operating system.


Remediation advice

Affected organisations are encouraged to review VMware Security Advisory VMSA-2022-0034 and apply any relevant updates or workarounds.



Last edited: 22 December 2022 12:05 pm