CVE-2022-31678: XEE
VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this VMware Cloud Foundation (NSX-V) vulnerability?
The vulnerability ID for this VMware Cloud Foundation (NSX-V) vulnerability is CVE-2022-31678.
What is the severity of CVE-2022-31678?
The severity of CVE-2022-31678 is critical with a CVSS score of 9.1.
What is the affected software for CVE-2022-31678?
The affected software for CVE-2022-31678 includes VMware Cloud Foundation (up to version 3.11) and VMware NSX Data Center (up to version 6.4.14).
What is the impact of CVE-2022-31678?
CVE-2022-31678 may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.
Where can I find more information about CVE-2022-31678?
You can find more information about CVE-2022-31678 in the VMware security advisory VMSA-2022-0027.