← Back

CVE-2023-20855

nvd nist
Published: Feb 22, 2023Modified: Mar 17, 2025

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sensitive information or possible escalation of privileges.

Affected (2)

2 products
Vrealize Automation
Vrealize Orchestrator
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
From 8.0 to 8.11.1
From 8.0 to 8.11.1

References (2)

Source: security@vmware.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.