Known vulnerabilities in vSphere Data Protection 6.1.4

Vendor: Broadcom
Version: 6.1.4
Software CPE: cpe:2.3:a:broadcom:vsphere_data_protection:*:*:*:*:*:*:*:*
Total vulnerabilities: 8
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting vSphere Data Protection version 6.1.4 vSphere Data Protection 6.1.4 is affected by 8 vulnerabilities: 2 high, 2 medium, 4 low Critical High Medium Low

Vulnerabilities (8)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU15991 - Exposure of sensitive information to an unauthorized actor
CVE-2018-11077
CWE-200 Low
No
No
6.0.9, 6.1.10 21.11.2018 SB2018112112
#VU15990 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2018-11076
CWE-78 Low
No
No
6.0.9, 6.1.9 21.11.2018 SB2018112112
#VU15989 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2018-11067
CWE-601 Low
No
No
6.0.9, 6.1.10 21.11.2018 SB2018112112
#VU15988 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2018-11066
CWE-78 High
No
No
6.0.9, 6.1.10 21.11.2018 SB2018112112
#VU14411 - Exposure of sensitive information to an unauthorized actor
CVE-2018-3620
CWE-200 Low
No
No
- 15.08.2018 SB2018081502
SB2018081506
SB2018081508
and 35 more
#VU9827 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2017-15550
CWE-22 Medium
No
No
- 02.01.2018 SB2018010204
#VU9826 - Unrestricted Upload of File with Dangerous Type
CVE-2017-15549
CWE-434 Medium
No
No
- 02.01.2018 SB2018010204
#VU9825 - Improper Authentication
CVE-2017-15548
CWE-287 High
No
No
- 02.01.2018 SB2018010204