Known vulnerabilities in VMware Aria Operations (formerly vRealize Operations) 6.7.0.11286837
Vendor:
VMware, Inc
Version:
6.7.0.11286837
Software CPE:
cpe:2.3:a:vmware:aria_operations:*:*:*:*:*:*:*:*
Website:
https://www.vmware.com
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.2
Vulnerabilities by Severity
8.18.7
9.0.2.0
9.0.1.0
9.0.0
8.18.6
8.18.5
8.18.4
8.18.3
8.18.2
8.18.1
8.18
8.17.2
8.17.1
8.16.1
8.14.1
8.14
8.16
8.12.5
8.12.4
8.12.3
8.12.2
8.12.1
8.12.0
8.10.9
8.10.8
8.10.7
8.10.6
8.10.5
8.10.3
8.10.2
8.6.11
8.6.9
8.6.8
8.6.7
8.6.6
8.6.5
8.10.4
8.6.10
8.6.4 21139695
8.6.4 20823815
8.10.1
8.10
8.6.4
8.6.3
8.6.2
8.6.1
8.6.0
8.5.0
8.4.0
8.3.0
8.2.0
8.1.1
8.1.0
8.0.1
8.0.0
7.0.0.11287810
6.7.0.11286837
6.6.1.11286876
7.0.0
6.7.0
6.6.1
6.6.0
6.5.1
6.5.0
6.4.0
6.1.2
6.2.0
6.0.0
6.3.0
6.2.1
6.2.0a
6.1.0
6.0.x
5.x
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU123149 - Permissions, Privileges, and Access Controls CVE-2026-22721 |
CWE-264 | Low | 8.18.6, 9.0.2.0 | 24.02.2026 |
SB2026022402 |
||
| #VU123148 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2026-22720 |
CWE-79 | Low | 8.18.6, 9.0.2.0 | 24.02.2026 |
SB2026022402 |
||
| #VU123146 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-22719 |
CWE-78 | Critical | 8.18.6, 9.0.2.0 | 24.02.2026 |
SB2026022402 |