CVE-2022-31710

vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrusted data which could result in a denial of service.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:vrealize_log_insight:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:vrealize_log_insight:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:05

Type Values Removed Values Added
References () https://www.vmware.com/security/advisories/VMSA-2023-0001.html - Patch, Vendor Advisory () https://www.vmware.com/security/advisories/VMSA-2023-0001.html - Patch, Vendor Advisory
Summary
  • (es) vRealize Log Insight contiene una vulnerabilidad de deserialización. Un actor malicioso no autenticado puede desencadenar de forma remota la deserialización de datos que no son de confianza, lo que podría provocar una denegación de servicio.

Information

Published : 2023-01-26 21:15

Updated : 2025-04-01 16:15


NVD link : CVE-2022-31710

Mitre link : CVE-2022-31710

CVE.ORG link : CVE-2022-31710


JSON object : View

Products Affected

vmware

  • vrealize_log_insight
CWE
CWE-502

Deserialization of Untrusted Data