ZDI-23-482: VMware Aria Operations for Logs Cluster Controller Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published Apr 24, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VMware Aria Operations for Logs. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
VMware Aria Operations for Logs
Event History
Apr 24, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-482?
The severity of ZDI-23-482 is rated at 89, indicating a high risk level.
2
How do I fix ZDI-23-482?
To fix ZDI-23-482, update your VMware Aria Operations for Logs to the latest version provided by VMware.
3
What systems are affected by ZDI-23-482?
ZDI-23-482 affects installations of VMware Aria Operations for Logs.
4
Can ZDI-23-482 be exploited without authentication?
Yes, ZDI-23-482 can be exploited by remote attackers without the need for authentication.
5
What type of vulnerability is ZDI-23-482?
ZDI-23-482 is a deserialization of untrusted data vulnerability that allows remote code execution.