CVE-2022-31710: High severity vmware vrealize log insight vulnerability
Published Jan 25, 2023
·Updated
vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrusted data which could result in a denial of service.
Affected Software
2 affected components
VMware vRealize Log Insight>=3.0<=4.8
VMware vRealize Log Insight>=8.0.0<8.10.2
Remediation
Event History
Jan 25, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Jan 26, 2023
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-31710?
CVE-2022-31710 is a deserialization vulnerability in vRealize Log Insight.
2
How can an unauthenticated malicious actor exploit CVE-2022-31710?
An unauthenticated malicious actor can remotely trigger the deserialization of untrusted data to exploit CVE-2022-31710.
3
What can be the impact of CVE-2022-31710?
CVE-2022-31710 can result in a denial of service (DoS) attack.
4
Which versions of vRealize Log Insight are affected by CVE-2022-31710?
vRealize Log Insight versions 3.0 through 4.8 and versions 8.0.0 through 8.10.2 are affected by CVE-2022-31710.
5
Where can I find more information about CVE-2022-31710?
More information about CVE-2022-31710 can be found at the following link: [VMware Security Advisory VMSA-2023-0001](https://www.vmware.com/security/advisories/VMSA-2023-0001.html).