Known vulnerabilities in VMware Tanzu Operations Manager - page 21

Vendor: Broadcom
Software CPE: cpe:2.3:a:broadcom:vmware_tanzu_operations_manager:*:*:*:*:*:*:*:*
Total vulnerabilities: 426
Public exploits: 15
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting VMware Tanzu Operations Manager VMware Tanzu Operations Manager is affected by 426 known vulnerabilities: 4 critical, 109 high, 164 medium, 149 low Critical High Medium Low

Vulnerabilities (426)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU63055 - Unchecked Return Value
CVE-2019-9704
CWE-252 Low
No
No
2.9.39, 2.10.40 11.05.2022 SB2022051133
SB2022051206
SB2022051207
and 7 more
#VU63054 - Allocation of Resources Without Limits or Throttling
CVE-2019-9705
CWE-770 Low
No
No
2.9.39, 2.10.40 11.05.2022 SB2022051133
SB2022051206
SB2022051207
and 7 more
#VU63053 - Use After Free
CVE-2019-9706
CWE-416 Low
No
No
2.9.39, 2.10.40 11.05.2022 SB2022051133
SB2022051206
SB2022051207
and 3 more
#VU61756 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-22965
CWE-94 Critical
Available
Exploited
2.8.20, 2.9.35, 2.10.35 31.03.2022 SB2022033109
SB2022040109
SB2022040110
and 78 more
#VU59319 - Origin Validation Error
CVE-2021-3618
CWE-346 Medium
No
No
2.7.25, 2.8.16, 2.9.12, 2.10.3 09.01.2022 SB2022010903
SB2022010904
SB2022010905
and 37 more
#VU58816 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-44228
CWE-94 Critical
Available
Exploited
2.10.23 10.12.2021 SB2021121003
SB2021121101
SB2021121201
and 338 more
#VU50040 - Heap-based Buffer Overflow
CVE-2021-3156
CWE-122 Low
Available
Exploited
2.7.29, 2.9.17, 2.10.6 26.01.2021 SB2021012632
SB2021012633
SB2021012634
and 55 more
#VU49883 - Improper Link Resolution Before File Access ('Link Following')
CVE-2021-23239
CWE-59 Low
No
No
2.7.29, 2.9.17, 2.10.6 12.01.2021 SB2021011282
SB2021011283
SB20210120114
and 14 more
#VU48944 - Memory corruption
CVE-2020-29361
CWE-119 Medium
No
No
2.7.28, 2.9.16, 2.10.5 14.12.2020 SB2020121401
SB2020121402
SB2020121422
and 22 more
#VU48945 - Memory corruption
CVE-2020-29362
CWE-119 Medium
No
No
2.7.28, 2.9.16, 2.10.5 14.12.2020 SB2020121401
SB2020121402
SB2020121423
and 21 more
#VU48946 - Memory corruption
CVE-2020-29363
CWE-119 Medium
No
No
2.7.28, 2.9.16, 2.10.5 14.12.2020 SB2020121401
SB2020121402
SB2020121424
and 17 more
#VU47741 - Heap-based Buffer Overflow
CVE-2020-15999
CWE-122 Critical
Available
Exploited
2.7.25, 2.9.13, 2.10.3 20.10.2020 SB2020102038
SB2020102039
SB2020102040
and 43 more
#VU30281 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2019-20807
CWE-78 Low
No
No
2.7.25, 2.9.12, 2.10.3 28.05.2020 SB2020052815
SB2020061148
SB2020110918
and 9 more
#VU19572 - Improper input validation
CVE-2019-1010204
CWE-20 Low
No
No
2.9.38, 2.10.39 31.07.2019 SB2019022402
SB2020042840
SB2022032836
and 7 more
#VU18058 - NULL Pointer Dereference
CVE-2019-9923
CWE-476 Low
No
No
2.7.28, 2.9.16, 2.10.5 22.03.2019 SB2019032204
SB2019041818
SB2021030306
and 10 more
#VU16782 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2018-20482
CWE-835 Low
No
No
2.7.28, 2.9.16, 2.10.5 02.01.2019 SB2018122607
SB2019010801
SB2019041818
and 8 more
#VU15935 - NULL Pointer Dereference
CVE-2018-19211
CWE-476 Low
No
No
2.9.41, 2.10.44 17.11.2018 SB2018111702
SB2018121002
SB2018121009
and 2 more
#VU12202 - Stack-based buffer overflow
CVE-2017-16879
CWE-121 High
No
No
2.9.41, 2.10.44 26.04.2018 SB2018041708
SB2017120121
SB2018012328
and 2 more
#VU31389 - Exposure of sensitive information to an unauthorized actor
CVE-2017-17087
CWE-200 Low
No
No
2.7.25, 2.9.12, 2.10.3 01.12.2017 SB2017120122
SB2020112312
SB2021111514
and 10 more
#VU7010 - Permissions, Privileges, and Access Controls
CVE-2017-9525
CWE-264 Low
No
No
2.9.39, 2.10.40 12.06.2017 SB2017061204
SB2017061209
SB2022051133
and 5 more


Showing elements 401 - 420 out of 426