First published: Wed Dec 14 2022(Updated: )
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vRealize Log Insight | <=8.10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-31703.
The severity of CVE-2022-31703 is high with a severity value of 7.5.
The affected software for CVE-2022-31703 is VMware vRealize Log Insight version up to 8.10.1.
CVE-2022-31703 allows an unauthenticated, malicious actor to inject files into the operating system of an impacted appliance, potentially leading to remote code execution.
Yes, VMware has released a security advisory with instructions on how to apply the necessary patches to fix CVE-2022-31703. Please refer to the official VMware security advisory (https://www.vmware.com/security/advisories/VMSA-2023-0001.html) for more details.