Known vulnerabilities in VMware Tanzu Application Service for VMs 2.7.46

Vendor: Broadcom
Version: 2.7.46
Software CPE: cpe:2.3:a:broadcom:vmware_tanzu_application_service_for_vms:*:*:*:*:*:*:*:*
Total vulnerabilities: 8
Public exploits: 1
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting VMware Tanzu Application Service for VMs version 2.7.46 VMware Tanzu Application Service for VMs 2.7.46 is affected by 8 vulnerabilities: 1 critical, 1 medium, 6 low Critical High Medium Low

Vulnerabilities (8)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU63055 - Unchecked Return Value
CVE-2019-9704
CWE-252 Low
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13 11.05.2022 SB2022051133
SB2022051206
SB2022051207
and 7 more
#VU63054 - Allocation of Resources Without Limits or Throttling
CVE-2019-9705
CWE-770 Low
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13 11.05.2022 SB2022051133
SB2022051206
SB2022051207
and 7 more
#VU63053 - Use After Free
CVE-2019-9706
CWE-416 Low
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13 11.05.2022 SB2022051133
SB2022051206
SB2022051207
and 3 more
#VU62883 - Use After Free
CVE-2020-35512
CWE-416 Low
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13 09.05.2022 SB2021021526
SB2022050921
SB2022051206
and 11 more
#VU61756 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-22965
CWE-94 Critical
Public exploit available
Exploited
2.10.29, 2.11.17, 2.12.10, 2.13.1 31.03.2022 SB2022033109
SB2022040109
SB2022040110
and 78 more
#VU48587 - Allocation of Resources Without Limits or Throttling
CVE-2020-8037
CWE-770 Medium
No
No
2.7.49, 2.10.31, 2.11.19, 2.12.12 04.11.2020 SB2020110433
SB2020112103
SB2021042704
and 12 more
#VU21949 - Out-of-bounds read
CVE-2018-16301
CWE-125 Low
No
No
2.7.49, 2.10.31, 2.11.19, 2.12.12 21.10.2019 SB2019102102
SB2019102103
SB2019100318
and 23 more
#VU7010 - Permissions, Privileges, and Access Controls
CVE-2017-9525
CWE-264 Low
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13 12.06.2017 SB2017061204
SB2017061209
SB2022051133
and 5 more