PT-2022-5903 · Vmware · Vrealize Network Insight+1
Published
2022-12-13
·
Updated
2023-03-01
·
CVE-2022-31703
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
vRealize Log Insight (affected versions not specified)
vRealize Network Insight (affected versions not specified)
Description
The issue concerns a Directory Traversal Vulnerability in the vRealize Log Insight and vRealize Network Insight. This vulnerability allows an unauthenticated, malicious actor to inject files into the operating system of an impacted appliance, potentially resulting in remote code execution. It also enables a malicious actor with network access to the vRNI REST API to read arbitrary files from the server.
Recommendations
For vRealize Log Insight, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For vRealize Network Insight, consider restricting access to the vRNI REST API to minimize the risk of exploitation. As a temporary workaround, avoid using the
downloadFile functionality until a patch is available.Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vrealize Log Insight
Vrealize Network Insight