vmware view-planner CVE-2021-21978 is a vulnerability in VMware View Planner
Published on March 3, 2021

VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file upload in logupload web application. An unauthorized attacker with network access to View Planner Harness could upload and execute a specially crafted file leading to remote code execution within the logupload container.

NVD


Products Associated with CVE-2021-21978

Want to know whenever a new CVE is published for VMware View Planner? stack.watch will email you.

 

Exploit Probability

EPSS
90.90%
Percentile
99.63%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.