Information disclosure in VMware Aria Operations (formerly vRealize Operations) - CVE-2022-31673
Published: August 10, 2022
Vulnerability identifier: #VU66352
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31673
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to exposure of hex dumps. A remote user can gain unauthorized access to sensitive information on the system.
Affected software
VMware Aria Operations (formerly vRealize Operations)
Dell Enterprise Hybrid Cloud
Dell Enterprise Hybrid Cloud
How to mitigate CVE-2022-31673
Install updates from vendor's website.
VMware Aria Operations (formerly vRealize Operations) - update to 8.6.4
Dell Enterprise Hybrid Cloud - update to 4.1.2
Dell Enterprise Hybrid Cloud - update to 4.1.2