Vrealize Operations
Vendor:
First CVE: Dec 29, 2016 · Active for 9 years
18
Total CVEs
More Total CVEs than 93% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Vrealize Operations over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 29, 2016
9 years ago
Most Recent CVE
May 12, 2023
1,169 days ago
CVE Severity & Scoring
Vrealize Operations18 CVEs
28%
56%
11%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (11.1%)
Network16 (88.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None17 (94.4%)
Unknown0 (0.0%)
Required1 (5.6%)
Privileges Required
Low4 (22.2%)
High8 (44.4%)
None6 (33.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-31673HIGH VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can create and leak hex dumps, leading to informat | Aug 10, 2022 | 8.8 | 28 | NO | NO |
CVE-2023-20856HIGH VMware vRealize Operations (vROps) contains a CSRF bypass vulnerability. A malicious user could execute actions on the vROps platform on behalf of the authenticated victim user. | Feb 1, 2023 | 8.8 | 27 | NO | NO |
CVE-2016-7457CRITICAL VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to gain privileges, or halt and remove virtual machines, via unspecified vectors. | Dec 29, 2016 | 10.0 | 25 | NO | NO |
CVE-2023-20878HIGH VMware Aria Operations contains a deserialization vulnerability. A malicious actor with administrative privileges can execute arbitrary commands and disrupt the system. | May 12, 2023 | 7.2 | 24 | NO | NO |
CVE-2022-31675HIGH VMware vRealize Operations contains an authentication bypass vulnerability. An unauthenticated malicious actor with network access may be able to create a user with administrative | Aug 10, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-31672HIGH VMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network access can escalate privileges to root. | Aug 10, 2022 | 7.2 | 24 | NO | NO |
CVE-2020-3943CRITICAL vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX RMI service which is not securely configured. An unauthenticated remote attacker | Feb 19, 2020 | 9.8 | 24 | NO | NO |
CVE-2023-20879MEDIUM VMware Aria Operations contains a Local privilege escalation vulnerability. A malicious actor with administrative privileges in the Aria Operations application can gain root access | May 12, 2023 | 6.7 | 23 | NO | NO |
CVE-2022-31707HIGH vRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSS | Dec 16, 2022 | 7.2 | 23 | NO | NO |
CVE-2023-20877HIGH VMware Aria Operations contains a privilege escalation vulnerability. An authenticated malicious user with ReadOnly privileges can perform code execution leading to privilege escal | May 12, 2023 | 8.8 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Vrealize Operations
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.6.0 | 3 | 7.6 | 0.6% | 0 | 0 |
| 8.10.0 | 5 | 7.3 | 0.7% | 0 | 0 |
| 6.3.0 | 2 | 9.3 | 2.6% | 0 | 0 |
| 6.2.1 | 2 | 9.3 | 2.6% | 0 | 0 |
| 6.2.0a | 2 | 9.3 | 2.6% | 0 | 0 |
| 6.1.0 | 2 | 9.3 | 2.6% | 0 | 0 |
| 6.0.0 | 2 | 9.3 | 2.6% | 0 | 0 |