Rewterz
Rewterz Threat Advisory – Multiple Apache Zeppelin Vulnerabilities
December 19, 2022
Rewterz
Rewterz Threat Advisory – ICS: Siemens SIPROTEC 5 Devices Vulnerability
December 19, 2022

Rewterz Threat Advisory – Multiple VMware vRealize Operations (vROps) Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2022-31707 CVSS:7.2

VMware vRealize Operations (vROps) could allow a remote authenticated attacker to gain elevated privileges on the system, caused by an unspecified flaw. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to gain root access to the underlying operating system.

CVE-2022-31708 CVSS:4.4

VMware vRealize Operations (vROps) could allow a local authenticated attacker to obtain sensitive information, caused by improper access control. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.

Impact

  • Privilege Escalation
  • Information Disclosure

Indicators Of Compromise

CVE

  • CVE-2022-31707
  • CVE-2022-31708

Affected Vendors

VMware

Affected Products

  • VMware vRealize Operations (vROps) 8.6
  • VMware vRealize Operations (vROps) 8.10

Remediation

Refer to VMware Security Advisory for patch, upgrade or suggested workaround information.

VMware Security Advisory