CVE-2022-31674: Infoleak
VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can access log files that lead to information disclosure.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-31674?
CVE-2022-31674 is an information disclosure vulnerability in VMware vRealize Operations.
What is the severity of CVE-2022-31674?
CVE-2022-31674 has a severity rating of 4.3, which is considered medium.
How can a low-privileged attacker exploit CVE-2022-31674?
A low-privileged attacker with network access can exploit CVE-2022-31674 to access log files and disclose sensitive information.
Which versions of VMware vRealize Operations are affected by CVE-2022-31674?
VMware vRealize Operations versions 8.0.0 to 8.6.4 are affected by CVE-2022-31674.
Is there a reference for more information about CVE-2022-31674?
Yes, you can find more information about CVE-2022-31674 in the VMware security advisory at this link: [VMware Security Advisory VMSA-2022-0022](https://www.vmware.com/security/advisories/VMSA-2022-0022.html).