← Back

Cloud Foundation

cloud_foundation

Vendor: Vmware • 135 CVEs

CVEs (135)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vmware
5Cloud Foundation
Identity ManagerVrealize Automation+2 more
Jun 17, 2026
Apr 13, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the...Show more
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the target system. Successful exploitation of this issue can lead to targeting victims.Show less
1Vmware
5Cloud Foundation
Identity ManagerVrealize Automation+2 more
Jun 17, 2026
Apr 13, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileg...Show more
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.Show less
1Vmware
5Cloud Foundation
Identity ManagerVrealize Automation+2 more
Jun 17, 2026
Apr 13, 2022
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally validat...Show more
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally validate a malicious JDBC URI.Show less
1Vmware
5Cloud Foundation
Identity ManagerVrealize Automation+2 more
Jun 17, 2026
Apr 13, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserial...Show more
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution.Show less
1Vmware
5Cloud Foundation
Identity ManagerVrealize Automation+2 more
Jun 17, 2026
Apr 13, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserial...Show more
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution.Show less
1Vmware
5Cloud Foundation
Identity ManagerVrealize Automation+2 more
Jun 17, 2026
Apr 11, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection tha...Show more
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.Show less
1Vmware
2Cloud Foundation
Vcenter Server
Jun 17, 2026
Mar 29, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sen...Show more
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.Show less
1Vmware
2Cloud Foundation
Nsx Data Center
Jun 17, 2026
Feb 16, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
VMware NSX Edge contains a CLI shell injection vulnerability. A malicious actor with SSH access to an NSX-Edge appliance can execute arbitrary commands on the operating system as root.
1Vmware
2Cloud Foundation
Esxi
Jun 17, 2026
Feb 16, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may exploit this issue to create a denial-of-service condition by overwhelming rhttpproxy servic...Show more
ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may exploit this issue to create a denial-of-service condition by overwhelming rhttpproxy service with multiple requests.Show less
1Vmware
2Cloud Foundation
Esxi
Jun 17, 2026
Feb 16, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privileges within the VMX process only, may be able to access settingsd servic...Show more
VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privileges within the VMX process only, may be able to access settingsd service running as a high privileged user.Show less
1Vmware
4Cloud Foundation
EsxiFusion+1 more
Jun 17, 2026
Feb 16, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as...Show more
VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.Show less
1Vmware
5Cloud Foundation
EsxiFusion+2 more
Jun 17, 2026
Feb 16, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code a...Show more
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.Show less
1Vmware
1Cloud Foundation
Jun 17, 2026
Feb 4, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text within multiple log files on the SDDC Manager. A malicious actor with root access on VMware Cloud Found...Show more
VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text within multiple log files on the SDDC Manager. A malicious actor with root access on VMware Cloud Foundation SDDC Manager may be able to view credentials in plaintext within one or more log files.Show less
1Vmware
4Cloud Foundation
EsxiFusion+1 more
Jun 17, 2026
Jan 4, 2022
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A maliciou...Show more
VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A malicious actor with access to a virtual machine with CD-ROM device emulation may be able to exploit this vulnerability in conjunction with other issues to execute code on the hypervisor from a virtual machine.Show less
1Vmware
2Cloud Foundation
Vcenter Server
Jun 17, 2026
Nov 24, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive infor...Show more
The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.Show less
1Vmware
2Cloud Foundation
Vcenter Server
Jun 17, 2026
Nov 10, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative access to vCenter Server may exploit thi...Show more
The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism. A malicious actor with non-administrative access to vCenter Server may exploit this issue to elevate privileges to a higher privileged group.Show less
1Vmware
3Cloud Foundation
Vrealize Log InsightVrealize Suite Lifecycle Manager
Jun 17, 2026
Oct 13, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interactive analytics export function. An authenticated malicious actor with non-administrative privileges m...Show more
VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interactive analytics export function. An authenticated malicious actor with non-administrative privileges may be able to embed untrusted data prior to exporting a CSV sheet through Log Insight which could be executed in user's environment.Show less
1Vmware
3Cloud Foundation
Vrealize OperationsVrealize Suite Lifecycle Manager
Jun 17, 2026
Oct 13, 2021
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability.
1Vmware
2Cloud Foundation
Vcenter Server
Jun 17, 2026
Sep 23, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this issue may allow an attacker to create a denial-of-service condition on vCenter Server.
1Vmware
2Cloud Foundation
Vcenter Server
Jun 17, 2026
Sep 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 5480 on vCenter Server may exploit this issue by sending a specially crafted json...Show more
The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 5480 on vCenter Server may exploit this issue by sending a specially crafted jsonrpc message to create a denial of service condition.Show less