Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid member role credentials may be able to perform a deserialization attack resulting in remote code execution.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vrealize_network_insight | Vmware | 6.2.0 (including) | 6.10.0 (including) |