VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.
2023-04-20T21:15:08.620
2025-02-05T16:15:34.130
Modified
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | vmware | aria_operations_for_logs | < 8.12.0 | Yes |
Application | vmware | cloud_foundation | ≤ 4.5 | Yes |