vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrusted data which could result in a denial of service.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vrealize_log_insight | Vmware | 3.0 (including) | 4.8 (including) |
Vrealize_log_insight | Vmware | 8.0.0 (including) | 8.10.2 (excluding) |