Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserialization attack resulting in remote code execution.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 07 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2025-01-07T14:56:37.775Z
Reserved: 2022-11-01T15:41:50.394Z
Link: CVE-2023-20888
Updated: 2024-08-02T09:21:33.416Z
Status : Modified
Published: 2023-06-07T15:15:09.263
Modified: 2025-01-07T16:15:29.400
Link: CVE-2023-20888
No data.
OpenCVE Enrichment
No data.
Weaknesses