Vulnerabilities
Vulnerable Software
VMware vRealize Automation (vRA) prior to 7.3.1 contains a vulnerability that may allow for a DOM-based cross-site scripting (XSS) attack. Exploitation of this issue may lead to the compromise of the vRA user's workstation.
CVSS Score
6.1
EPSS Score
0.002
Published
2018-04-13
VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs. Exploitation of this issue may lead to the hijacking of a valid vRA user's session.
CVSS Score
9.8
EPSS Score
0.015
Published
2018-04-13
VMware vRealize Automation (7.3 and 7.2) and vSphere Integrated Containers (1.x before 1.3) contain a deserialization vulnerability via Xenon. Successful exploitation of this issue may allow remote attackers to execute arbitrary code on the appliance.
CVSS Score
9.8
EPSS Score
0.276
Published
2018-01-29


Contact Us

Shodan ® - All rights reserved