PT-2024-1101 · Vmware · Vmware Aria Automation+1
Published
2024-01-16
·
Updated
2025-10-30
·
CVE-2023-34063
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
VMware Aria Automation (formerly vRealize Automation) versions prior to the fixed version
VMware Cloud Foundation (formerly Aria Automation) versions prior to the fixed version
Description
The issue is related to a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerability, leading to unauthorized access to remote organizations and workflows.
Recommendations
For VMware Aria Automation (formerly vRealize Automation) versions prior to the fixed version: Update to the latest version to resolve the issue.
For VMware Cloud Foundation (formerly Aria Automation) versions prior to the fixed version: Update to the latest version to resolve the issue.
As a temporary workaround, consider restricting access to sensitive workflows and organizations until a patch is available.
Fix
Improper Access Control
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vmware Aria Automation
Vmware Cloud Foundation