imPC@ndo IT

Tracker / CVE-2021-22036

CVE-2021-22036

Medium 6.5

VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. A malicious actor may be able to redirect victim to an attacker controlled domain due to improper path handling in vRealize Orchestrator leading to sensitive information disclosure.

Affected products and versions

vmware vrealize_automation · 8.0 → 8.6
vmware vrealize_orchestrator · 8.0 → 8.6

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References