CVE-2023-20855

CVSS V2 None CVSS V3 None
Description
VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sensitive information or possible escalation of privileges.
Overview
  • CVE ID
  • CVE-2023-20855
  • Assigner
  • security@vmware.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-02-22T00:15:11
  • Last Modified Date
  • 2023-03-03T14:04:52
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:vmware:vrealize_automation:*:*:*:*:*:*:*:* 1 OR 8.0 8.11.1
cpe:2.3:a:vmware:vrealize_orchestrator:*:*:*:*:*:*:*:* 1 OR 8.0 8.11.1
References
Reference URL Reference Tags
https://www.vmware.com/security/advisories/VMSA-2023-0005.html Patch Vendor Advisory
History
Created Old Value New Value Data Type Notes
2023-04-17 08:04:23 Added to TrackCVE
2023-04-17 08:04:26 Weakness Enumeration new