PT-2021-5049 · Vmware · Vmware Vrealize Operations Tenant App

Dhiraj Shrikant Datar

·

Published

2021-10-19

·

Updated

2022-07-12

·

CVE-2021-22034

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions VMware vRealize Operations Tenant App versions prior to 8.6
Description The issue is related to an Information Disclosure Vulnerability in the monitoring tool for virtual infrastructure. It is associated with the disclosure of information in an error data area. Exploitation of this issue may allow a remote attacker to disclose protected information.
Recommendations For versions prior to 8.6, update to version 8.6 or later to resolve the issue.

Fix

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05820
CVE-2021-22034

Affected Products

Vmware Vrealize Operations Tenant App