VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sensitive information or possible escalation of privileges.
2023-02-22T00:15:11.513
2025-03-17T19:15:17.593
Modified
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | vmware | vrealize_automation | < 8.11.1 | Yes |
Application | vmware | vrealize_orchestrator | < 8.11.1 | Yes |