Hunting for bugs in VMware: View Planner and vRealize Business for Cloud
swarm.ptsecurity.com | vulnerability | #cloud | #rce | #vulnerability-research | #vmware | #cve | #command-injection
Summary
PT SWARM uncovers unauthenticated RCEs in VMware View Planner (CVE-2021-21978) and vRealize Business for Cloud (CVE-2021-21984). The View Planner flaw traces to an unauthenticated WSGI log-upload endpoint in its dockerized web stack, leading to command execution.
- Published
- Collected
Skip to content