CVE-2023-20855: XEE
VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sensitive information or possible escalation of privileges.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-20855?
CVE-2023-20855 is a vulnerability in VMware vRealize Orchestrator that allows a malicious actor to bypass XML parsing restrictions and gain unauthorized access to sensitive information or potentially elevate privileges.
What is the severity of CVE-2023-20855?
The severity of CVE-2023-20855 is rated as high, with a CVSS score of 8.8.
Which software versions are affected by CVE-2023-20855?
VMware vRealize Automation and VMware vRealize Orchestrator versions between 8.0 and 8.11.1 are affected by CVE-2023-20855.
How can a malicious actor exploit CVE-2023-20855?
A malicious actor with non-administrative access to vRealize Orchestrator can exploit CVE-2023-20855 by using specially crafted input to bypass XML parsing restrictions.
Is there a patch or fix available for CVE-2023-20855?
Yes, VMware has provided patches to address the CVE-2023-20855 vulnerability. More information can be found in the official VMware security advisory.