Known vulnerabilities in VMware Tanzu Application Service for VMs 2.8.18
Vendor:
Broadcom
Software:
VMware Tanzu Application Service for VMs
Version:
2.8.18
Software CPE:
cpe:2.3:a:broadcom:vmware_tanzu_application_service_for_vms:*:*:*:*:*:*:*:*
Website:
https://www.broadcom.com/
Total vulnerabilities:
11
Public exploits:
5
Known exploited (KEV):
3
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
5.0.14
2.11.58
2.13.40
5.0.13
5.0.12
2.13.39
2.11.57
5.0.11
2.11.56
2.13.38
2.11.55
2.13.37
5.0.10
5.0.9
5.0.8
2.13.36
2.11.54
2.13.35
2.11.53
5.0.7
5.0.6
2.13.34
2.11.52
5.0.5
2.13.33
2.11.51
2.11.50
5.0.4
2.13.32
4.0.11
4.0.12
3.0.20
5.0.3
2.13.31
2.11.49
5.0.2
2.13.30
2.11.48
5.0.1
3.0.19
2.13.29
2.11.47
4.0.9
4.0.10
4.0.8
5.0.0
3.0.18
2.13.28
2.11.46
3.0.17
2.13.27
2.11.45
3.0.16
2.13.26
2.11.44
4.0.6
3.0.15
2.13.25
2.11.43
4.0.5
3.0.14
2.13.24
2.11.42
4.0.4
3.0.13
2.13.23
2.11.41
2.13.22
2.11.40
4.0.3
3.0.12
4.0.2
3.0.11
2.13.21
2.11.39
4.0.1
3.0.10
4.0.0
2.13.20
2.11.38
3.0.9
2.13.19
2.11.37
2.13.18
2.12.25
2.11.36
3.0.8
2.11.35
3.0.7
2.13.17
2.12.24
3.0.6
2.13.16
2.12.23
2.11.34
3.0.5
2.13.15
2.12.22
2.11.33
3.0.4
2.13.14
2.12.21
2.11.32
3.0.3
2.13.13
2.12.20
2.11.31
3.0.2
2.13.12
2.11.30
3.0.1
2.13.11
2.12.19
2.11.29
2.11.28
2.13.10
2.12.18
2.11.27
3.0.0
2.13.9
2.12.17
2.11.26
2.7.53
2.13.8
2.12.16
2.11.23
2.10.35
-
2.12.15
2.13.7
2.11.22
2.10.34
2.7.52
2.13.6
2.12.14
2.11.21
2.10.33
2.7.51
2.13.5
2.12.13
2.11.20
2.10.32
2.7.50
2.13.4
2.13.3
2.12.12
2.11.19
2.10.31
2.7.49
2.13.2
2.12.11
2.11.18
2.10.30
2.13.1
2.12.10
2.11.17
2.10.29
2.12.9
2.11.16
2.10.28
2.7.48
2.13.0
2.12.8
2.11.15
2.10.27
2.7.47
2.12.7
2.11.14
2.10.26
2.7.46
2.12.6
2.11.13
2.10.25
2.9.31
2.8.31
2.7.45
2.6.23
2.12.5
2.11.12
2.10.24
2.9.30
2.8.30
2.7.44
2.11.11
2.12.4
2.10.23
2.7.43
2.6.22
2.9.29
2.8.29
2.10.22
2.12.3
2.11.10
2.7.42
2.12.2
2.11.9
2.10.21
2.7.41
2.12.1
2.10.20
2.11.8
2.9.28
2.7.40
2.12.0
2.11.7
2.10.19
2.9.27
2.7.39
2.11.6
2.10.18
2.9.26
2.7.38
2.11.5
2.10.17
2.9.25
2.7.37
2.11.4
2.10.16
2.9.24
2.7.36
2.11.3
2.10.15
2.9.23
2.7.35
2.11.2
2.10.14
2.9.22
2.8.28
2.7.34
2.11.1
2.10.13
2.9.21
2.8.27
2.7.33
2.8.26
2.7.32
2.10.12
2.9.20
2.11.0
2.10.11
2.7.31
2.9.19
2.8.25
2.10.10
2.9.18
2.8.24
2.7.30
2.10.9
2.9.17
2.8.23
2.7.29
2.7.28
2.8.22
2.10.8
2.10.7
2.10.6
2.10.5
2.10.4
2.9.16
2.9.15
2.9.14
2.9.13
2.9.12
2.9.0
2.8.21
2.8.20
2.8.19
2.8.18
2.8.4
2.7.27
2.7.26
2.7.25
2.7.24
2.6.21
2.6.20
2.6.19
2.6.18
2.6.17
2.6.16
2.6.15
2.6.14
2.6.13
2.6.12
2.6.11
2.6.10
2.6.9
2.6.8
2.6.7
2.6.6
2.6.5
2.6.4
2.6.3
2.6.2
2.6.1
2.6.0
2.5.21
2.5.20
2.5.19
2.5.18
2.5.17
2.5.16
2.5.15
2.5.14
2.5.13
2.5.12
2.5.11
2.5.10
2.5.9
2.5.8
2.5.7
2.5.6
2.5.5
2.5.4
2.5.3
2.5.2
2.5.1
2.5.0
2.4.16
2.4.15
2.4.14
2.4.13
2.4.12
2.4.11
2.4.10
2.4.9
2.4.8
2.4.7
2.4.6
2.4.5
2.4.4
2.4.3
2.4.2
2.4.1
2.4.0
2.3.18
2.3.17
2.3.16
2.3.15
2.3.14
2.3.13
2.3.12
2.3.11
2.3.10
2.3.9
2.3.8
2.3.7
2.3.6
2.3.5
2.3.4
2.3.3
2.10.3
2.10.2
2.10.1
2.9.11
2.9.10
2.9.9
2.8.17
2.8.16
2.8.15
2.7.23
2.7.22
2.7.21
2.10.0
2.9.8
2.9.7
2.9.6
2.9.5
2.9.4
2.9.3
2.9.2
2.9.1
2.8.14
2.8.13
2.8.12
2.8.11
2.8.10
2.8.9
2.8.8
2.8.7
2.8.6
2.8.5
2.8.3
2.8.2
2.8.1
2.8.0
2.7.20
2.7.19
2.7.18
2.7.17
2.7.16
2.7.15
2.7.12
2.7.11
2.7.10
2.7.9
2.7.8
2.7.7
2.7.6
2.7.5
2.7.4
2.7.3
2.7.2
2.7.1
2.7.0
Vulnerabilities (11)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU61756 - Improper Control of Generation of Code ('Code Injection') CVE-2022-22965 |
CWE-94 | Critical | 2.10.29, 2.11.17, 2.12.10, 2.13.1 | 31.03.2022 |
SB2022033109 SB2022040109 SB2022040110 and 78 more |
||
| #VU58816 - Improper Control of Generation of Code ('Code Injection') CVE-2021-44228 |
CWE-94 | Critical | 2.7.42, 2.10.22, 2.11.10, 2.12.3 | 10.12.2021 |
SB2021121003 SB2021121101 SB2021121201 and 338 more |
||
| #VU58173 - Resource exhaustion CVE-2021-22101 |
CWE-400 | Medium | 2.7.40, 2.9.28, 2.10.20, 2.11.8, 2.12.1 | 16.11.2021 |
SB2021111602 SB2021111603 |
||
| #VU48746 - Improper input validation CVE-2020-5423 |
CWE-20 | Medium | 2.7.29, 2.9.17, 2.10.9 | 02.12.2020 |
SB2020120207 SB2020120208 |
||
| #VU47741 - Heap-based Buffer Overflow CVE-2020-15999 |
CWE-122 | Critical | 2.7.28, 2.8.22, 2.9.16, 2.10.8 | 20.10.2020 |
SB2020102038 SB2020102039 SB2020102040 and 43 more |
||
| #VU47546 - Improper Access Control CVE-2020-12352 |
CWE-284 | Medium | 2.7.27, 2.8.21, 2.9.15, 2.10.7 | 13.10.2020 |
SB2020101322 SB2020101803 SB2020101804 and 35 more |
||
| #VU47545 - Improper input validation CVE-2020-12351 |
CWE-20 | Medium | 2.7.27, 2.8.21, 2.9.15, 2.10.7 | 13.10.2020 |
SB2020101322 SB2020101803 SB2020101804 and 32 more |
||
| #VU48592 - Improper Neutralization of CRLF Sequences ('CRLF Injection') CVE-2020-26116 |
CWE-93 | Medium | 2.7.27, 2.8.21, 2.9.15, 2.10.7 | 27.09.2020 |
SB2020092711 SB2020112308 SB2020112309 and 34 more |
||
| #VU46181 - Incorrect Permission Assignment for Critical Resource CVE-2020-5417 |
CWE-732 | Medium | 2.7.28, 2.8.22, 2.9.16, 2.10.8 | 01.09.2020 |
SB2020090120 SB2020111701 |
||
| #VU30281 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2019-20807 |
CWE-78 | Low | 2.7.27, 2.8.21, 2.9.15, 2.10.7 | 28.05.2020 |
SB2020052815 SB2020061148 SB2020110918 and 9 more |
||
| #VU31389 - Exposure of sensitive information to an unauthorized actor CVE-2017-17087 |
CWE-200 | Low | 2.7.27, 2.8.21, 2.9.15, 2.10.7 | 01.12.2017 |
SB2017120122 SB2020112312 SB2021111514 and 10 more |