Remote Code Execution Vulnerability in VMware vRealize Business for Cloud

  • Original Issue Date:May 13, 2021
  • Severity Rating: HIGH

Software Affected

  • VMware vRealize Business for Cloud versions prior to 7.6.0

Overview

  • A vulnerability has been reported in VMware vRealize Business for Cloud which could be exploited by a remote attacker to execute arbitrary code on a targeted system.

Description

  • This vulnerability exists in VMware vRealize Business for Cloud due to an unauthorized end point.
  • Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the targeted system.

Solution

  •       Update to version 7.6.0 as mentioned in VMware advisory:

https://www.vmware.com/security/advisories/VMSA-2021-0007.html

References

https://www.tenable.com/cve/CVE-2021-21984

CVE Name

  •       CVE-2021-21984

Disclaimer

  •       The information provided herein is on “as is” basis, without warranty of any kind.

Leave a Reply