Severity
High
Analysis Summary
An authenticated actor may be able to send malicious traffic to VMware Cloud Director which may lead to arbitrary remote code execution. This vulnerability can be exploited through the HTML5- and Flex-based UIs, the API Explorer interface and API access.
Impact
Code injection
Affected Vendors
VMware
Affected Products
VMware Cloud Director
Remediation
Refer to VMware security advisory for the list of affected products and upgraded patches.
https://www.vmware.com/security/advisories/VMSA-2020-0010.html

