CVE Database
/

CVE-2021-21978

Back to search

CVE-2021-21978

Published: Mar 3, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file upload in logupload web application. An unauthorized attacker with network access to View Planner Harness could upload and execute a specially crafted file leading to remote code execution within the logupload container.

VendorProductVersions

n/a

VMware View Planner

affected
VMware View Planner 4.x prior to 4.6 Security Patch 1

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now