Input validation error in VMware Cloud Director - CVE-2022-22966

 

Input validation error in VMware Cloud Director - CVE-2022-22966

Published: April 15, 2022


Vulnerability identifier: #VU62349
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22966
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input. A remote authenticated user with network access to the VMware Cloud Director tenant or provider can send specially crafted input to the application and and execute arbitrary code on the system.


Affected software

VMware Cloud Director

How to mitigate CVE-2022-22966

Install updates from vendor's website.

VMware Cloud Director - addressed in versions 10.1.4.1, 10.2.2.3, 10.3.3

External References

Related Security Bulletins