Back to search
CVE-2021-21978
Published: Mar 3, 2021
Modified: Aug 3, 2024
PUBLISHED
Description
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file upload in logupload web application. An unauthorized attacker with network access to View Planner Harness could upload and execute a specially crafted file leading to remote code execution within the logupload container.
| Vendor | Product | Versions |
|---|---|---|
n/a | VMware View Planner | affected VMware View Planner 4.x prior to 4.6 Security Patch 1 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now