Known vulnerabilities in Cloud Foundation 4.4

Vendor: Broadcom
Version: 4.4
Software CPE: cpe:2.3:a:broadcom:vmware_cloud_foundation:*:*:*:*:*:*:*:*
Total vulnerabilities: 15
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Cloud Foundation version 4.4 Cloud Foundation 4.4 is affected by 15 vulnerabilities: 1 critical, 2 medium, 12 low Critical High Medium Low

Vulnerabilities (15)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU86668 - Permissions, Privileges, and Access Controls
CVE-2024-22235
CWE-264 Low
No
No
- 21.02.2024 SB2024022102
#VU76057 - Permissions, Privileges, and Access Controls
CVE-2023-20880
CWE-264 Low
No
No
- 12.05.2023 SB2023051209
#VU76056 - Permissions, Privileges, and Access Controls
CVE-2023-20879
CWE-264 Low
No
No
- 12.05.2023 SB2023051209
#VU76055 - Deserialization of Untrusted Data
CVE-2023-20878
CWE-502 Low
No
No
- 12.05.2023 SB2023051209
#VU76053 - Permissions, Privileges, and Access Controls
CVE-2023-20877
CWE-264 Medium
No
No
- 12.05.2023 SB2023051209
#VU65991 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-31665
CWE-94 Low
No
No
- 02.08.2022 SB2022080254
SB2022080255
SB2022080257
and 3 more
#VU65990 - Permissions, Privileges, and Access Controls
CVE-2022-31664
CWE-264 Low
No
No
- 02.08.2022 SB2022080254
SB2022080255
SB2022080257
and 3 more
#VU65989 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-31663
CWE-79 Low
No
No
- 02.08.2022 SB2022080254
SB2022080255
SB2022080257
and 3 more
#VU65988 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-31662
CWE-22 Medium
No
No
- 02.08.2022 SB2022080254
SB2022080255
SB2022080256
and 4 more
#VU65987 - Permissions, Privileges, and Access Controls
CVE-2022-31661
CWE-264 Low
No
No
- 02.08.2022 SB2022080254
SB2022080255
SB2022080257
and 3 more
#VU65986 - Permissions, Privileges, and Access Controls
CVE-2022-31660
CWE-264 Low
Public exploit available
No
- 02.08.2022 SB2022080254
SB2022080255
SB2022080257
and 3 more
#VU65985 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-31659
CWE-89 Low
No
No
- 02.08.2022 SB2022080254
SB2022080255
SB2022080257
and 3 more
#VU65984 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-31658
CWE-94 Low
No
No
- 02.08.2022 SB2022080254
SB2022080255
SB2022080257
and 3 more
#VU65983 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2022-31657
CWE-601 Low
No
No
- 02.08.2022 SB2022080254
SB2022080255
SB2022080257
and 3 more
#VU65957 - Improper Authentication
CVE-2022-31656
CWE-287 Critical
No
No
- 02.08.2022 SB2022080229
SB2022081126