Known vulnerabilities in VMware Tanzu Operations Manager - page 12

Vendor: Broadcom
Software CPE: cpe:2.3:a:broadcom:vmware_tanzu_operations_manager:*:*:*:*:*:*:*:*
Total vulnerabilities: 426
Public exploits: 15
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting VMware Tanzu Operations Manager VMware Tanzu Operations Manager is affected by 426 known vulnerabilities: 4 critical, 109 high, 164 medium, 149 low Critical High Medium Low

Vulnerabilities (426)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU77164 - Exposure of sensitive information to an unauthorized actor
CVE-2023-32681
CWE-200 Medium
Available
No
3.0.11 12.06.2023 SB2023061224
SB2023061306
SB2023061514
and 114 more
#VU75741 - Improper input validation
CVE-2023-1667
CWE-20 Medium
No
No
3.0.12 04.05.2023 SB2023050456
SB2023050501
SB2023052441
and 75 more
#VU75740 - Improper Authentication
CVE-2023-2283
CWE-287 High
No
No
3.0.12 04.05.2023 SB2023050456
SB2023050501
SB2023052441
and 84 more
#VU75538 - Exposure of sensitive information to an unauthorized actor
CVE-2023-1786
CWE-200 Medium
No
No
2.7.24, 2.8.14, 2.9.11, 2.10.57, 3.0.8 27.04.2023 SB2023042703
SB2023042706
SB2023051101
and 16 more
#VU75486 - Improper input validation
CVE-2023-29007
CWE-20 Low
Available
No
3.0.9 25.04.2023 SB2023042553
SB2023042610
SB2023042629
and 48 more
#VU75485 - Insufficient Verification of Data Authenticity
CVE-2023-25815
CWE-345 Low
No
No
3.0.9 25.04.2023 SB2023042553
SB2023042610
SB2023042638
and 40 more
#VU75484 - Improper Link Resolution Before File Access ('Link Following')
CVE-2023-25652
CWE-59 Low
No
No
3.0.9 25.04.2023 SB2023042553
SB2023042610
SB2023042629
and 48 more
#VU74337 - Out-of-bounds read
CVE-2023-26253
CWE-125 Low
No
No
3.0.11 03.04.2023 SB2023040340
SB2023040343
SB2023061304
and 3 more
#VU74197 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-28487
CWE-78 Low
No
No
3.0.8 30.03.2023 SB2023033028
SB2023033038
SB2023033039
and 28 more
#VU74196 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-28486
CWE-78 Low
No
No
3.0.8 30.03.2023 SB2023033028
SB2023033038
SB2023033039
and 31 more
#VU72618 - Improper input validation
CVE-2023-24329
CWE-20 Medium
No
No
2.10.57, 2.10.59, 3.0.6, 3.0.12 28.02.2023 SB2023022819
SB2023022822
SB2023030832
and 158 more
#VU71620 - Heap-based Buffer Overflow
CVE-2022-48281
CWE-122 High
No
No
2.7.25, 2.8.16, 2.9.12, 2.10.39 30.01.2023 SB2023013012
SB2023013014
SB2023013015
and 27 more
#VU69585 - Integer overflow
CVE-2022-3970
CWE-190 High
No
No
2.7.25, 2.8.16, 2.9.12, 2.10.39 25.11.2022 SB2022112501
SB2022112507
SB2022112821
and 33 more
#VU64709 - Heap-based Buffer Overflow
CVE-2022-2207
CWE-122 Medium
No
No
3.0.8 27.06.2022 SB2022062719
SB2022071351
SB2022080610
and 17 more
#VU62025 - Memory corruption
CVE-2022-0729
CWE-119 High
No
No
3.0.8 08.04.2022 SB2022040826
SB2022040828
SB2022060635
and 9 more
#VU60796 - Heap-based Buffer Overflow
CVE-2022-0714
CWE-122 High
No
No
3.0.8 22.02.2022 SB2022022221
SB2022040828
SB2022060635
and 9 more
#VU51446 - Memory corruption
CVE-2020-35524
CWE-119 High
No
No
2.7.25, 2.8.16, 2.9.12, 2.10.39 14.03.2021 SB2021031406
SB2021031409
SB2021050104
and 12 more
#VU51445 - Integer overflow
CVE-2020-35523
CWE-190 High
No
No
2.7.25, 2.8.16, 2.9.12, 2.10.39 14.03.2021 SB2021031406
SB2021031409
SB2021050104
and 12 more
#VU22615 - Integer overflow
CVE-2019-17546
CWE-190 High
No
No
2.7.25, 2.8.16, 2.9.12, 2.10.39 10.11.2019 SB2019101413
SB2019101414
SB2020012302
and 18 more
#VU20390 - Integer overflow
CVE-2019-14973
CWE-190 Medium
No
No
2.7.25, 2.8.16, 2.9.12, 2.10.39 26.08.2019 SB2019082710
SB2019110501
SB2020012302
and 15 more


Showing elements 221 - 240 out of 426