April 21, 2023, 2:04 p.m. | Satnam Narang

Cyber Exposure Alerts www.tenable.com

VMware issues advisory to address two flaws in its VMware Aria Operations for Logs solution, including a critical deserialization flaw assigned a CVSSv3 score of 9.8.


Background


On April 20, VMware published an advisory (VMSA-2023-0007) to address two vulnerabilities in VMware Aria Operations for Logs, formerly known as vRealize Log Insight, a centralized log management solution.












CVEDescriptionCVSSv3VPR*
CVE-2023-20864Deserialization Vulnerability in VMware Aria Operations for Logs9.88.4
CVE-2023-20865OS Command Injection in VMware Aria Operations …

address advisory april aria critical cve cve-2023-20864 deserialization flaw flaws insight log logs operations score solution vmware vmware aria operations for logs vrealize vrealize log insight vulnerabilities vulnerability

Social Engineer For Reverse Engineering Exploit Study

@ Independent study | Remote

Security Engineer II- Full stack Java with React

@ JPMorgan Chase & Co. | Hyderabad, Telangana, India

Cybersecurity SecOps

@ GFT Technologies | Mexico City, MX, 11850

Senior Information Security Advisor

@ Sun Life | Sun Life Toronto One York

Contract Special Security Officer (CSSO) - Top Secret Clearance

@ SpaceX | Hawthorne, CA

Early Career Cyber Security Operations Center (SOC) Analyst

@ State Street | Quincy, Massachusetts