First published: Wed Jan 25 2023(Updated: )
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
Credit: security@vmware.com security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vRealize Log Insight | >=3.0<=4.8 | |
VMware vRealize Log Insight | >=8.0.0<8.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vRealize Log Insight vulnerability is CVE-2022-31706.
The severity of CVE-2022-31706 is critical, with a severity value of 9.8.
CVE-2022-31706 is a Directory Traversal Vulnerability in vRealize Log Insight that allows an unauthenticated, malicious actor to inject files into the operating system, potentially leading to remote code execution.
CVE-2022-31706 affects VMware vRealize Log Insight versions between 3.0 and 4.8, as well as versions between 8.0.0 and 8.10.2.
To fix the Directory Traversal Vulnerability in vRealize Log Insight, it is recommended to apply the necessary security patches and updates provided by VMware.