Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-20855


VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sensitive information or possible escalation of privileges.


Published

2023-02-22T00:15:11.513

Last Modified

2025-03-17T19:15:17.593

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-611
  • Type: Secondary
    CWE-611

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application vmware vrealize_automation < 8.11.1 Yes
Application vmware vrealize_orchestrator < 8.11.1 Yes

References