#VU51179 Improper Authorization in VMware View Planner - CVE-2021-21978
Published: March 3, 2021 / Updated: October 18, 2021
VMware View Planner
VMware, Inc
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to missing authorization within the View Planner Harness feature in logupload web application. A remote non-authenticated attacker can upload and execute arbitrary file on the system.
Successful exploitation of the vulnerability may allow an attacker to execute arbitrary code within the logupload container.