سيبرانا

قاعدة الثغرات (CVE)

CVE-2026-22719

حقن أوامر دون مصادقة في VMware Aria Operations

عاليةمُستغلة فعليًاKEVالتصحيح متوفر: غير متوفر بعد

ثغرة حقن أوامر في Aria Operations (vRealize Operations سابقًا) تسمح لمهاجم غير مصادَق بتنفيذ أوامر عشوائية وصولًا إلى تنفيذ شفرة عن بُعد على منصة المراقبة.

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.  To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001  Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001

المنتجات المتأثرة

Productالإصدارات المتأثرةتم الإصلاح في
VMware Aria Operations

التغطية على سيبرانا