Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Hunting for bugs in VMware: View Planner and vRealize Business for Cloud

Summary

PT SWARM uncovers unauthenticated RCEs in VMware View Planner (CVE-2021-21978) and vRealize Business for Cloud (CVE-2021-21984). The View Planner flaw traces to an unauthenticated WSGI log-upload endpoint in its dockerized web stack, leading to command execution.
Published
Collected

original ↗

Related coverage

back