CVE-2023-20856: CSRF
Published Feb 1, 2023
·Updated
VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of the authenticated victim user.
Affected Software
1 affected component
VMware vRealize Operations>=8.6.0<=8.6.4
Event History
Feb 1, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this VMware vRealize Operations vulnerability?
The vulnerability ID for this VMware vRealize Operations vulnerability is CVE-2023-20856.
2
What is the severity level of CVE-2023-20856?
The severity level of CVE-2023-20856 is high with a score of 8.8.
3
How does the CSRF bypass vulnerability in VMware vRealize Operations work?
The CSRF bypass vulnerability in VMware vRealize Operations allows a malicious user to execute actions on the platform on behalf of the authenticated victim user.
4
Which version of VMware vRealize Operations is affected by CVE-2023-20856?
CVE-2023-20856 affects VMware vRealize Operations version 8.6.0 to 8.6.4.
5
Where can I find more information about CVE-2023-20856?
You can find more information about CVE-2023-20856 on the official VMware security advisories page: https://www.vmware.com/security/advisories/VMSA-2023-0002.html