Known vulnerabilities in VMware Tanzu Application Service for VMs - page 20

Vendor: Broadcom
Software CPE: cpe:2.3:a:broadcom:vmware_tanzu_application_service_for_vms:*:*:*:*:*:*:*:*
Total vulnerabilities: 483
Public exploits: 18
Known exploited (KEV): 6
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting VMware Tanzu Application Service for VMs VMware Tanzu Application Service for VMs is affected by 483 known vulnerabilities: 5 critical, 112 high, 201 medium, 165 low Critical High Medium Low

Vulnerabilities (483)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU64922 - Missing Encryption of Sensitive Data
CVE-2022-2097
CWE-311 Low
No
No
2.7.52, 2.10.34, 2.11.22, 2.12.16, 2.13.7 05.07.2022 SB2022070509
SB2022070522
SB2022070531
and 112 more
#VU64909 - Improper Verification of Cryptographic Signature
CVE-2022-34903
CWE-347 Medium
No
No
2.7.52, 2.10.34, 2.11.22, 2.12.16, 2.13.7 04.07.2022 SB2022070429
SB2022070443
SB2022070521
and 58 more
#VU64559 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-2068
CWE-78 Medium
No
No
2.7.52, 2.10.34, 2.11.22, 2.12.16, 2.13.7 21.06.2022 SB2022062120
SB2022062125
SB2022062236
and 135 more
#VU63711 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-1664
CWE-22 Medium
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.15, 2.13.5 26.05.2022 SB2022052610
SB2022052613
SB2022052622
and 9 more
#VU63627 - Memory corruption
CVE-2021-36690
CWE-119 Low
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13, 2.13.5 25.05.2022 SB2022050533
SB2022071831
SB2022092034
and 16 more
#VU63343 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-29155
CWE-89 High
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13, 2.13.5 17.05.2022 SB2022051725
SB2022051731
SB2022051919
and 27 more
#VU63009 - Incorrect Implementation of Authentication Algorithm
CVE-2022-27782
CWE-303 Medium
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13, 2.13.5 11.05.2022 SB2022051112
SB2022051136
SB2022051170
and 68 more
#VU63008 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2022-27781
CWE-835 Medium
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13, 2.13.5 11.05.2022 SB2022051112
SB2022051136
SB2022051170
and 36 more
#VU63007 - Improper input validation
CVE-2022-27780
CWE-20 Low
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13, 2.13.5 11.05.2022 SB2022051112
SB2022051136
SB2022051170
and 14 more
#VU62768 - Uncontrolled Memory Allocation
CVE-2022-1473
CWE-789 Low
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13, 2.13.5 03.05.2022 SB2022050315
SB2022050436
SB2022050532
and 18 more
#VU62767 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2022-1434
CWE-300 Low
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13, 2.13.5 03.05.2022 SB2022050315
SB2022050436
SB2022050532
and 10 more
#VU62766 - Security Features
CVE-2022-1343
CWE-254 Medium
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13, 2.13.5 03.05.2022 SB2022050315
SB2022050436
SB2022050532
and 14 more
#VU62765 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-1292
CWE-78 Medium
Available
No
2.7.50, 2.10.32, 2.11.20, 2.12.13, 2.13.5 03.05.2022 SB2022050315
SB2022050436
SB2022050503
and 141 more
#VU62644 - Exposure of sensitive information to an unauthorized actor
CVE-2022-27776
CWE-200 Low
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13, 2.13.5 27.04.2022 SB2022042706
SB2022042803
SB2022042904
and 62 more
#VU62643 - Resource Management Errors
CVE-2022-27775
CWE-399 Low
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13, 2.13.5 27.04.2022 SB2022042706
SB2022042803
SB2022042904
and 30 more
#VU62641 - Exposure of sensitive information to an unauthorized actor
CVE-2022-27774
CWE-200 Medium
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13, 2.13.5 27.04.2022 SB2022042706
SB2022042803
SB2022042904
and 57 more
#VU62640 - Improper Authentication
CVE-2022-22576
CWE-287 Medium
No
No
2.7.50, 2.10.32, 2.11.20, 2.12.13, 2.13.5 27.04.2022 SB2022042706
SB2022042803
SB2022042904
and 60 more
#VU62258 - Untrusted Search Path
CVE-2022-24765
CWE-426 Low
No
No
2.7.49, 2.10.31, 2.11.19, 2.12.12, 2.13.4 12.04.2022 SB2022041262
SB2022041264
SB2022041265
and 44 more
#VU61671 - Memory corruption
CVE-2018-25032
CWE-119 Medium
No
No
2.7.49, 2.10.31, 2.11.19, 2.12.12, 2.13.4 28.03.2022 SB2022032844
SB2022032845
SB2022033018
and 192 more
#VU20961 - Improper Validation of Certificate with Host Mismatch
CVE-2019-13050
CWE-297 Medium
No
No
2.7.52, 2.10.34, 2.11.22, 2.12.15, 2.13.7 10.09.2019 SB2019062907
SB2019091018
SB2019081531
and 12 more


Showing elements 381 - 400 out of 483