Known vulnerabilities in VMware Tanzu Operations Manager 2.9.15

Vendor: Broadcom
Version: 2.9.15
Software CPE: cpe:2.3:a:broadcom:vmware_tanzu_operations_manager:*:*:*:*:*:*:*:*
Total vulnerabilities: 12
Public exploits: 1
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting VMware Tanzu Operations Manager version 2.9.15 VMware Tanzu Operations Manager 2.9.15 is affected by 12 vulnerabilities: 1 critical, 4 high, 4 medium, 3 low Critical High Medium Low

Vulnerabilities (12)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU64274 - Out-of-bounds read
CVE-2022-29458
CWE-125 Medium
No
No
2.9.41, 2.10.44, 2.10.59, 3.0.11 14.06.2022 SB2022061418
SB2022061419
SB2022072842
and 29 more
#VU62002 - Improper input validation
CVE-2022-1271
CWE-20 High
No
No
2.9.38, 2.10.39 08.04.2022 SB2022040803
SB2022040804
SB2022040822
and 134 more
#VU61756 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-22965
CWE-94 Critical
Public exploit available
Exploited
2.8.20, 2.9.35, 2.10.35 31.03.2022 SB2022033109
SB2022040109
SB2022040110
and 78 more
#VU61671 - Memory corruption
CVE-2018-25032
CWE-119 Medium
No
No
2.9.41, 2.10.44 28.03.2022 SB2022032844
SB2022032845
SB2022033018
and 192 more
#VU57577 - Out-of-bounds write
CVE-2021-39537
CWE-787 High
No
No
2.9.41, 2.10.44, 2.10.59, 3.0.11 21.10.2021 SB2021102119
SB2022061419
SB2021102025
and 18 more
#VU51741 - Improper Handling of Exceptional Conditions
CVE-2021-28831
CWE-755 Medium
No
No
2.9.39, 2.10.40, 2.10.61 26.03.2021 SB2021032622
SB2021032626
SB2021032627
and 25 more
#VU21793 - Buffer over-read
CVE-2019-17595
CWE-126 Medium
No
No
2.9.41, 2.10.44, 2.10.59, 3.0.11 15.10.2019 SB2019101515
SB2019112401
SB2019112402
and 23 more
#VU21792 - Heap-based Buffer Overflow
CVE-2019-17594
CWE-122 High
No
No
2.9.41, 2.10.44, 2.10.59, 3.0.11 15.10.2019 SB2019101515
SB2019112401
SB2019112402
and 23 more
#VU19572 - Improper input validation
CVE-2019-1010204
CWE-20 Low
No
No
2.9.38, 2.10.39 31.07.2019 SB2019022402
SB2020042840
SB2022032836
and 7 more
#VU18290 - Improper input validation
CVE-2018-1000654
CWE-20 Low
No
No
2.9.38, 2.10.39 17.04.2019 SB2018082017
SB2019060302
SB2019060502
and 6 more
#VU15935 - NULL Pointer Dereference
CVE-2018-19211
CWE-476 Low
No
No
2.9.41, 2.10.44 17.11.2018 SB2018111702
SB2018121002
SB2018121009
and 2 more
#VU12202 - Stack-based buffer overflow
CVE-2017-16879
CWE-121 High
No
No
2.9.41, 2.10.44 26.04.2018 SB2018041708
SB2017120121
SB2018012328
and 2 more