← Back

Vrealize Orchestrator

vrealize_orchestrator

Vendor: Vmware • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vmware
2Vrealize Automation
Vrealize Orchestrator
Jun 17, 2026
Feb 22, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsi...Show more
VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sensitive information or possible escalation of privileges.Show less
1Vmware
2Vrealize Automation
Vrealize Orchestrator
Jun 17, 2026
Oct 13, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. A malicious actor may be able to redirect victim to an attacker controlled domain due to improper pa...Show more
VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. A malicious actor may be able to redirect victim to an attacker controlled domain due to improper path handling in vRealize Orchestrator leading to sensitive information disclosure.Show less
1Vmware
2Vcenter Orchestrator
Vrealize Orchestrator
May 6, 2026
Dec 21, 2015
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
Serialized-object interfaces in VMware vRealize Orchestrator 6.x, vCenter Orchestrator 5.x, vRealize Operations 6.x, vCenter Operations 5.x, and vCenter Application Discovery Manager (vADM) 7.x allow remote attackers to...Show more
Serialized-object interfaces in VMware vRealize Orchestrator 6.x, vCenter Orchestrator 5.x, vRealize Operations 6.x, vCenter Operations 5.x, and vCenter Application Discovery Manager (vADM) 7.x allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.Show less