Known vulnerabilities in Cloud Foundation 4.2 - page 2

Vendor: Broadcom
Version: 4.2
Software CPE: cpe:2.3:a:broadcom:vmware_cloud_foundation:*:*:*:*:*:*:*:*
Total vulnerabilities: 33
Public exploits: 7
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Cloud Foundation version 4.2 Cloud Foundation 4.2 is affected by 33 vulnerabilities: 4 critical, 4 high, 7 medium, 18 low Critical High Medium Low

Vulnerabilities (33)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU61934 - Cross-Site Request Forgery (CSRF)
CVE-2022-22959
CWE-352 High
No
No
- 06.04.2022 SB2022040612
SB2022040613
SB2022040614
and 4 more
#VU61933 - Deserialization of Untrusted Data
CVE-2022-22958
CWE-502 Low
No
No
- 06.04.2022 SB2022040612
SB2022040613
SB2022040614
and 4 more
#VU61932 - Deserialization of Untrusted Data
CVE-2022-22957
CWE-502 Low
Public exploit available
No
- 06.04.2022 SB2022040612
SB2022040613
SB2022040614
and 4 more
#VU60191 - Cleartext Storage of Sensitive Information
CVE-2022-22939
CWE-312 Low
No
No
4.3.1.1 31.01.2022 SB2022013117
#VU58816 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-44228
CWE-94 Critical
Public exploit available
Exploited
- 10.12.2021 SB2021121003
SB2021121101
SB2021121201
and 338 more
#VU56807 - Permissions, Privileges, and Access Controls
CVE-2021-22018
CWE-264 Medium
No
No
4.3.1 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 2 more
#VU56800 - Improper Authentication
CVE-2021-22011
CWE-287 Medium
No
No
3.10.2.2, 4.3.1 21.09.2021 SB2021092117
SB2021092118
SB2021092918
and 3 more
#VU55616 - Unprotected primary channel
CVE-2021-22003
CWE-419 Low
No
No
- 05.08.2021 SB2021080524
SB2021080525
SB2021080526
and 2 more
#VU55615 - Server-Side Request Forgery (SSRF)
CVE-2021-22002
CWE-918 High
No
No
- 05.08.2021 SB2021080524
SB2021080525
SB2021080526
and 3 more
#VU54816 - Out-of-bounds read
CVE-2021-21995
CWE-125 Medium
No
No
3.10.2 13.07.2021 SB2021071366
SB2021071373
SB2021101003
and 2 more
#VU54814 - Improper Authentication
CVE-2021-21994
CWE-287 High
No
No
3.10.2 13.07.2021 SB2021071366
SB2021071373
SB2021101003
and 3 more
#VU53596 - Improper Authentication
CVE-2021-21986
CWE-287 Medium
No
No
3.10.2.1, 4.2.1 26.05.2021 SB2021052634
SB2021101003
SB2021120331
and 3 more
#VU53595 - Improper input validation
CVE-2021-21985
CWE-20 Critical
Public exploit available
Exploited
3.10.2.1, 4.2.1 26.05.2021 SB2021052634
SB2021101003
SB2021120331
and 3 more


Showing elements 21 - 40 out of 33