PT-2021-7283 · Vmware · Vmware Vrealize Orchestrator

Marek Takáč

·

Published

2021-10-12

·

Updated

2021-10-20

·

CVE-2021-22036

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions VMware vRealize Orchestrator versions 8.x prior to 8.6
Description The issue is related to improper path handling, which may allow a malicious actor to redirect victims to an attacker-controlled domain, potentially leading to sensitive information disclosure. This is due to an open redirect vulnerability in the platform.
Recommendations For versions 8.x prior to 8.6, update to version 8.6 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive information and monitoring for suspicious redirects.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05137
CVE-2021-22036

Affected Products

Vmware Vrealize Orchestrator