Known vulnerabilities in VMware Tanzu Operations Manager 2.10.24

Vendor: Broadcom
Version: 2.10.24
Software CPE: cpe:2.3:a:broadcom:vmware_tanzu_operations_manager:*:*:*:*:*:*:*:*
Total vulnerabilities: 21
Public exploits: 2
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting VMware Tanzu Operations Manager version 2.10.24 VMware Tanzu Operations Manager 2.10.24 is affected by 21 vulnerabilities: 1 critical, 6 high, 10 medium, 4 low Critical High Medium Low

Vulnerabilities (21)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU78540 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2023-32001
CWE-367 Low
No
No
2.10.61 21.07.2023 SB2023072135
SB2023072137
SB2023072138
and 17 more
#VU78454 - Untrusted Search Path
CVE-2023-38408
CWE-426 Medium
Public exploit available
No
2.10.61 20.07.2023 SB2023072068
SB2023072073
SB2023072074
and 73 more
#VU77612 - Resource exhaustion
CVE-2023-2828
CWE-400 Medium
No
No
2.10.60, 3.0.12 21.06.2023 SB2023062155
SB2023062201
SB2023062601
and 66 more
#VU77610 - Resource Management Errors
CVE-2023-2911
CWE-399 Medium
No
No
2.10.60, 3.0.12 21.06.2023 SB2023062155
SB2023062201
SB2023062205
and 15 more
#VU76238 - Expected Behavior Violation
CVE-2023-28322
CWE-440 Medium
No
No
2.10.61 17.05.2023 SB2023051752
SB2023051760
SB2023051761
and 88 more
#VU76237 - Improper Certificate Validation
CVE-2023-28321
CWE-295 Medium
No
No
2.10.61 17.05.2023 SB2023051752
SB2023051760
SB2023051761
and 99 more
#VU72703 - Improper Control of Filename for Include/Require Statement in PHP Program
CVE-2023-2603
CWE-98 High
No
No
2.10.59, 3.0.12 01.03.2023 SB2023030118
SB2023060126
SB2023061452
and 87 more
#VU68829 - Resource Management Errors
CVE-2022-40304
CWE-399 Medium
No
No
2.10.51, 3.0.2 30.10.2022 SB2022103005
SB2022103006
SB2022103007
and 90 more
#VU68828 - Integer overflow
CVE-2022-40303
CWE-190 High
No
No
2.10.51, 3.0.2 30.10.2022 SB2022103005
SB2022103006
SB2022103007
and 88 more
#VU64274 - Out-of-bounds read
CVE-2022-29458
CWE-125 Medium
No
No
2.9.41, 2.10.44, 2.10.59, 3.0.11 14.06.2022 SB2022061418
SB2022061419
SB2022072842
and 29 more
#VU62002 - Improper input validation
CVE-2022-1271
CWE-20 High
No
No
2.9.38, 2.10.39 08.04.2022 SB2022040803
SB2022040804
SB2022040822
and 134 more
#VU61671 - Memory corruption
CVE-2018-25032
CWE-119 Medium
No
No
2.9.41, 2.10.44 28.03.2022 SB2022032844
SB2022032845
SB2022033018
and 192 more
#VU57577 - Out-of-bounds write
CVE-2021-39537
CWE-787 High
No
No
2.9.41, 2.10.44, 2.10.59, 3.0.11 21.10.2021 SB2021102119
SB2022061419
SB2021102025
and 18 more
#VU51741 - Improper Handling of Exceptional Conditions
CVE-2021-28831
CWE-755 Medium
No
No
2.9.39, 2.10.40, 2.10.61 26.03.2021 SB2021032622
SB2021032626
SB2021032627
and 25 more
#VU21793 - Buffer over-read
CVE-2019-17595
CWE-126 Medium
No
No
2.9.41, 2.10.44, 2.10.59, 3.0.11 15.10.2019 SB2019101515
SB2019112401
SB2019112402
and 23 more
#VU21792 - Heap-based Buffer Overflow
CVE-2019-17594
CWE-122 High
No
No
2.9.41, 2.10.44, 2.10.59, 3.0.11 15.10.2019 SB2019101515
SB2019112401
SB2019112402
and 23 more
#VU19572 - Improper input validation
CVE-2019-1010204
CWE-20 Low
No
No
2.9.38, 2.10.39 31.07.2019 SB2019022402
SB2020042840
SB2022032836
and 7 more
#VU18290 - Improper input validation
CVE-2018-1000654
CWE-20 Low
No
No
2.9.38, 2.10.39 17.04.2019 SB2018082017
SB2019060302
SB2019060502
and 6 more
#VU15935 - NULL Pointer Dereference
CVE-2018-19211
CWE-476 Low
No
No
2.9.41, 2.10.44 17.11.2018 SB2018111702
SB2018121002
SB2018121009
and 2 more
#VU12202 - Stack-based buffer overflow
CVE-2017-16879
CWE-121 High
No
No
2.9.41, 2.10.44 26.04.2018 SB2018041708
SB2017120121
SB2018012328
and 2 more


Showing elements 1 - 20 out of 21