CVE-2021-22036

VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. A malicious actor may be able to redirect victim to an attacker controlled domain due to improper path handling in vRealize Orchestrator leading to sensitive information disclosure.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:vrealize_automation:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:vrealize_orchestrator:*:*:*:*:*:*:*:*

Information

Published : 2021-10-13 09:15

Updated : 2021-10-20 06:42


NVD link : CVE-2021-22036

Mitre link : CVE-2021-22036


JSON object : View

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

Advertisement

dedicated server usa

Products Affected

vmware

  • vrealize_automation
  • vrealize_orchestrator