VMware Cloud Foundation Directory Traversal Vulnerability

Vulnerability

A directory traversal vulnerability has been identified in VMware Cloud Foundation. This vulnerability allows a malicious actor with network access to port 443 to exploit the issue and access certain internal services. VMware has rated the severity of this vulnerability as high, with a CVSSv3 base score of 8.2.

Impact

Exploitation of this vulnerability could lead to unauthorized access to internal services, potentially allowing for further exploitation or access to sensitive information.

Remediation

To address this vulnerability, users should apply the updates listed in the 'Fixed Version' column of the VMware Cloud Foundation 5.2.1.2 Response Matrix. For version 4.5.x, refer to Knowledge Base article KB398008.

Added: Jun 5, 2025, 11:44 PM
Updated: Jun 6, 2025, 12:18 AM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.