vmware cloud-foundation CVE-2021-22035 vulnerability in VMware Products
Published on October 13, 2021

VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interactive analytics export function. An authenticated malicious actor with non-administrative privileges may be able to embed untrusted data prior to exporting a CSV sheet through Log Insight which could be executed in user's environment.

NVD


Products Associated with CVE-2021-22035

Want to know whenever a new CVE is published for VMware products? stack.watch will email you.

 
 
 

Exploit Probability

EPSS
0.27%
Percentile
50.03%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.