PT-2024-1101 · Vmware · Vmware Aria Automation+1

Published

2024-01-16

·

Updated

2025-10-30

·

CVE-2023-34063

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions VMware Aria Automation (formerly vRealize Automation) versions prior to the fixed version VMware Cloud Foundation (formerly Aria Automation) versions prior to the fixed version
Description The issue is related to a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerability, leading to unauthorized access to remote organizations and workflows.
Recommendations For VMware Aria Automation (formerly vRealize Automation) versions prior to the fixed version: Update to the latest version to resolve the issue. For VMware Cloud Foundation (formerly Aria Automation) versions prior to the fixed version: Update to the latest version to resolve the issue. As a temporary workaround, consider restricting access to sensitive workflows and organizations until a patch is available.

Fix

Improper Access Control

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-00382
CVE-2023-34063

Affected Products

Vmware Aria Automation
Vmware Cloud Foundation