Vrealize Log Insight

Vendor:

First CVE: Jul 3, 2016 · Active for 10 years

15
Total CVEs
More Total CVEs than 93% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 77% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Vrealize Log Insight over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 3, 2016
10 years ago
Most Recent CVE
Jan 26, 2023
1,279 days ago

CVE Severity & Scoring

Vrealize Log Insight15 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (53.3%)
Unknown0 (0.0%)
Required7 (46.7%)
Privileges Required
Low4 (26.7%)
High2 (13.3%)
None9 (60.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which
Jan 26, 20239.890NOYES
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance w
Jan 26, 20239.888NOYES
VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and application information without authentic
Jan 26, 20235.349NOYES
vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrusted data which could result in a
Jan 26, 20237.525NONO
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which
Dec 14, 20227.525NONO
VMware vRealize Log Insight (4.7.x before 4.7.1 and 4.6.x before 4.6.2) contains a vulnerability due to improper authorization in the user registration method. Successful exploitat
Nov 13, 20187.224NONO
Cross-site request forgery (CSRF) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to hijack the authentication of unspecified victims
Jul 3, 20168.822NONO
Directory traversal vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.6.0 allows remote attackers to read arbitrary files via unspecified vectors.
Aug 31, 20165.321NONO
VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improper input sanitization in configurations.
Jul 12, 20225.420NONO
VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user input validation. An attacker with user privileges may be ab
Aug 30, 20215.419NONO

Exploit Exposure

Signals from CVEs in this product scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
20.0% of CVEs· 98th percentile
Nuclei
3 CVEs
20.0% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (15 CVEs).

Media Mentions

Signals from CVEs in this product scope (15 CVEs).

Top CNAs Publishing CVEs For Vrealize Log Insight

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.3.127.50.7%00
3.336.71.5%00
3.0.127.50.7%00
3.036.71.5%00
2.5.127.50.7%00
2.536.71.5%00
2.0.536.71.5%00
2.036.71.5%00