Known vulnerabilities in vCenter Server 6.7 U3p

Vendor: Broadcom
Version: 6.7 U3p
Software CPE: cpe:2.3:a:broadcom:vcenter-server:*:*:*:*:*:*:*:*
Total vulnerabilities: 5
Public exploits: 2
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting vCenter Server version 6.7 U3p vCenter Server 6.7 U3p is affected by 5 vulnerabilities: 1 critical, 3 medium, 1 low Critical High Medium Low

Vulnerabilities (5)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU70080 - Improper input validation
CVE-2022-31698
CWE-20 Medium
Public exploit available
No
6.5 U3u, 6.7 U3s, 7.0 U3i 09.12.2022 SB2022120903
SB2023040648
#VU70079 - Information Exposure Through Log Files
CVE-2022-31697
CWE-532 Low
No
No
6.5 U3u, 6.7 U3s, 7.0 U3i 09.12.2022 SB2022120903
SB2023040648
SB2023051945
and 1 more
#VU65211 - Server-Side Request Forgery (SSRF)
CVE-2022-22982
CWE-918 Medium
No
No
6.5 U3t, 6.7 U3r, 7.0 U3f 12.07.2022 SB2022071255
SB2022081126
#VU58816 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-44228
CWE-94 Critical
Public exploit available
Exploited
- 10.12.2021 SB2021121003
SB2021121101
SB2021121201
and 338 more
#VU58104 - Permissions, Privileges, and Access Controls
CVE-2021-22048
CWE-264 Medium
No
No
- 10.11.2021 SB2021111014
SB2022010422