Known vulnerabilities in VMware Tanzu Application Service for VMs 2.7.5

Vendor: Broadcom
Version: 2.7.5
Software CPE: cpe:2.3:a:broadcom:vmware_tanzu_application_service_for_vms:*:*:*:*:*:*:*:*
Total vulnerabilities: 21
Public exploits: 5
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting VMware Tanzu Application Service for VMs version 2.7.5 VMware Tanzu Application Service for VMs 2.7.5 is affected by 21 vulnerabilities: 3 critical, 9 medium, 9 low Critical High Medium Low

Vulnerabilities (21)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU63055 - Unchecked Return Value
CVE-2019-9704
CWE-252 Low
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13 11.05.2022 SB2022051133
SB2022051206
SB2022051207
and 7 more
#VU63054 - Allocation of Resources Without Limits or Throttling
CVE-2019-9705
CWE-770 Low
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13 11.05.2022 SB2022051133
SB2022051206
SB2022051207
and 7 more
#VU63053 - Use After Free
CVE-2019-9706
CWE-416 Low
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13 11.05.2022 SB2022051133
SB2022051206
SB2022051207
and 3 more
#VU62883 - Use After Free
CVE-2020-35512
CWE-416 Low
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13 09.05.2022 SB2021021526
SB2022050921
SB2022051206
and 11 more
#VU61756 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-22965
CWE-94 Critical
Public exploit available
Exploited
2.10.29, 2.11.17, 2.12.10, 2.13.1 31.03.2022 SB2022033109
SB2022040109
SB2022040110
and 78 more
#VU58816 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-44228
CWE-94 Critical
Public exploit available
Exploited
2.7.42, 2.10.22, 2.11.10, 2.12.3 10.12.2021 SB2021121003
SB2021121101
SB2021121201
and 338 more
#VU58173 - Resource exhaustion
CVE-2021-22101
CWE-400 Medium
No
No
2.7.40, 2.9.28, 2.10.20, 2.11.8, 2.12.1 16.11.2021 SB2021111602
SB2021111603
#VU48746 - Improper input validation
CVE-2020-5423
CWE-20 Medium
No
No
2.7.29, 2.9.17, 2.10.9 02.12.2020 SB2020120207
SB2020120208
#VU48587 - Allocation of Resources Without Limits or Throttling
CVE-2020-8037
CWE-770 Medium
No
No
2.7.49, 2.10.31, 2.11.19, 2.12.12 04.11.2020 SB2020110433
SB2020112103
SB2021042704
and 12 more
#VU47741 - Heap-based Buffer Overflow
CVE-2020-15999
CWE-122 Critical
Public exploit available
Exploited
2.7.28, 2.8.22, 2.9.16, 2.10.8 20.10.2020 SB2020102038
SB2020102039
SB2020102040
and 43 more
#VU47546 - Improper Access Control
CVE-2020-12352
CWE-284 Medium
Public exploit available
No
2.7.27, 2.8.21, 2.9.15, 2.10.7 13.10.2020 SB2020101322
SB2020101803
SB2020101804
and 35 more
#VU47545 - Improper input validation
CVE-2020-12351
CWE-20 Medium
Public exploit available
No
2.7.27, 2.8.21, 2.9.15, 2.10.7 13.10.2020 SB2020101322
SB2020101803
SB2020101804
and 32 more
#VU48592 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2020-26116
CWE-93 Medium
No
No
2.7.27, 2.8.21, 2.9.15, 2.10.7 27.09.2020 SB2020092711
SB2020112308
SB2020112309
and 34 more
#VU46658 - Improper input validation
CVE-2020-5420
CWE-20 Medium
No
No
2.7.23, 2.8.17, 2.9.11, 2.10.3 11.09.2020 SB2020090382
SB2020091117
#VU46181 - Incorrect Permission Assignment for Critical Resource
CVE-2020-5417
CWE-732 Medium
No
No
2.7.28, 2.8.22, 2.9.16, 2.10.8 01.09.2020 SB2020090120
SB2020111701
#VU45794 - Expired pointer dereference
CVE-2020-8231
CWE-825 Low
No
No
2.7.23, 2.8.17, 2.9.11, 2.10.3 20.08.2020 SB2020081916
SB2020082001
SB2020081920
and 29 more
#VU30281 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2019-20807
CWE-78 Low
No
No
2.7.27, 2.8.21, 2.9.15, 2.10.7 28.05.2020 SB2020052815
SB2020061148
SB2020110918
and 9 more
#VU21949 - Out-of-bounds read
CVE-2018-16301
CWE-125 Low
No
No
2.7.49, 2.10.31, 2.11.19, 2.12.12 21.10.2019 SB2019102102
SB2019102103
SB2019100318
and 23 more
#VU31389 - Exposure of sensitive information to an unauthorized actor
CVE-2017-17087
CWE-200 Low
No
No
2.7.27, 2.8.21, 2.9.15, 2.10.7 01.12.2017 SB2017120122
SB2020112312
SB2021111514
and 10 more
#VU7010 - Permissions, Privileges, and Access Controls
CVE-2017-9525
CWE-264 Low
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13 12.06.2017 SB2017061204
SB2017061209
SB2022051133
and 5 more


Showing elements 1 - 20 out of 21