Vulnerability Details CVE-2023-20855
VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sensitive information or possible escalation of privileges.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.6%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2023-20855
-
cpe:2.3:a:vmware:vrealize_automation:8.0
-
cpe:2.3:a:vmware:vrealize_automation:8.1
-
cpe:2.3:a:vmware:vrealize_automation:8.2
-
cpe:2.3:a:vmware:vrealize_automation:8.3
-
cpe:2.3:a:vmware:vrealize_automation:8.4
-
cpe:2.3:a:vmware:vrealize_automation:8.5
-
cpe:2.3:a:vmware:vrealize_automation:8.6
-
cpe:2.3:a:vmware:vrealize_orchestrator:*