Known vulnerabilities in Cloud Foundation 3.10.1.1

Vendor: Broadcom
Version: 3.10.1.1
Software CPE: cpe:2.3:a:broadcom:vmware_cloud_foundation:*:*:*:*:*:*:*:*
Total vulnerabilities: 23
Public exploits: 5
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Cloud Foundation version 3.10.1.1 Cloud Foundation 3.10.1.1 is affected by 23 vulnerabilities: 1 critical, 3 high, 9 medium, 10 low Critical High Medium Low

Vulnerabilities (23)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU61935 - Incorrect Default Permissions
CVE-2022-22960
CWE-276 Low
Public exploit available
Exploited
- 06.04.2022 SB2022040612
SB2022040613
SB2022040614
and 4 more
#VU61934 - Cross-Site Request Forgery (CSRF)
CVE-2022-22959
CWE-352 High
No
No
- 06.04.2022 SB2022040612
SB2022040613
SB2022040614
and 4 more
#VU61933 - Deserialization of Untrusted Data
CVE-2022-22958
CWE-502 Low
No
No
- 06.04.2022 SB2022040612
SB2022040613
SB2022040614
and 4 more
#VU61932 - Deserialization of Untrusted Data
CVE-2022-22957
CWE-502 Low
Public exploit available
No
- 06.04.2022 SB2022040612
SB2022040613
SB2022040614
and 4 more
#VU60191 - Cleartext Storage of Sensitive Information
CVE-2022-22939
CWE-312 Low
No
No
4.3.1.1 31.01.2022 SB2022013117
#VU58816 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-44228
CWE-94 Critical
Public exploit available
Exploited
- 10.12.2021 SB2021121003
SB2021121101
SB2021121201
and 338 more
#VU56809 - Improper input validation
CVE-2021-22020
CWE-20 Low
No
No
3.10.2.2 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 2 more
#VU56808 - Improper input validation
CVE-2021-22019
CWE-20 Medium
No
No
3.10.2.2 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 2 more
#VU56806 - Improper Authorization
CVE-2021-22017
CWE-285 Medium
No
Exploited
3.10.2.2 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 3 more
#VU56805 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-22016
CWE-79 Low
No
No
3.10.2.2 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 3 more
#VU56804 - Incorrect Default Permissions
CVE-2021-22015
CWE-276 Low
Public exploit available
No
3.10.2.2 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 2 more
#VU56803 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-22014
CWE-94 Low
No
No
3.10.2.2 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 2 more
#VU56800 - Improper Authentication
CVE-2021-22011
CWE-287 Medium
No
No
3.10.2.2, 4.3.1 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 3 more
#VU56799 - Resource exhaustion
CVE-2021-22010
CWE-400 Medium
No
No
3.10.2.2 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 3 more
#VU56798 - Resource exhaustion
CVE-2021-22009
CWE-400 Medium
No
No
3.10.2.2 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 3 more
#VU56797 - Exposure of sensitive information to an unauthorized actor
CVE-2021-22008
CWE-200 Medium
No
No
3.10.2.2 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 3 more
#VU56796 - Exposure of sensitive information to an unauthorized actor
CVE-2021-22007
CWE-200 Low
No
No
3.10.2.2 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 2 more
#VU56795 - Improper Authorization
CVE-2021-22006
CWE-285 High
Public exploit available
No
3.10.2.2 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 3 more
#VU56793 - Server-Side Request Forgery (SSRF)
CVE-2021-21993
CWE-918 Medium
No
No
3.10.2.2 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 3 more
#VU56792 - Improper input validation
CVE-2021-21992
CWE-20 Medium
No
No
3.10.2.2 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 3 more


Showing elements 1 - 20 out of 23