Information disclosure in VMware Aria Operations (formerly vRealize Operations) - CVE-2022-31674
Published: August 10, 2022
Vulnerability identifier: #VU66353
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31674
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote user can gain unauthorized access to sensitive information on the system.
Affected software
VMware Aria Operations (formerly vRealize Operations)
Dell Enterprise Hybrid Cloud
Dell Enterprise Hybrid Cloud
How to mitigate CVE-2022-31674
Install updates from vendor's website.
VMware Aria Operations (formerly vRealize Operations) - update to 8.6.4
Dell Enterprise Hybrid Cloud - update to 4.1.2
Dell Enterprise Hybrid Cloud - update to 4.1.2