CVE-2022-31711: Infoleak
Published Jan 25, 2023
·Updated
VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and application information without authentication.
Affected Software
2 affected components
VMware vRealize Log Insight>=3.0<=4.8
VMware vRealize Log Insight>=8.0.0<8.10.2
Remediation
Event History
Jan 25, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Jan 26, 2023
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-31711?
CVE-2022-31711 is an Information Disclosure Vulnerability in VMware vRealize Log Insight.
2
How does CVE-2022-31711 affect VMware vRealize Log Insight?
CVE-2022-31711 allows a malicious actor to remotely collect sensitive session and application information without authentication.
3
What is the severity of CVE-2022-31711?
The severity of CVE-2022-31711 is medium with a CVSS score of 5.3.
4
What versions of VMware vRealize Log Insight are affected by CVE-2022-31711?
CVE-2022-31711 affects VMware vRealize Log Insight versions 3.0 to 4.8, and versions 8.0.0 to 8.10.2.
5
How can I fix CVE-2022-31711 in VMware vRealize Log Insight?
To fix CVE-2022-31711, VMware recommends updating to the latest version of vRealize Log Insight.