Description
Due to vulnerabilities in Log4j library used by vCenter, an unauthenticated attacker can leak sensitive information or execute arbitrary code on the system.
Remediation
Upgrade to the latest version of VMware vCenter
References
Related Vulnerabilities
Missing Authentication Check in SAP Solution Manager
WordPress Plugin Duplicator-WordPress Migration Arbitrary File Disclosure (0.3.0)
VMware vCenter Server Unauthorized Remote Code Execution
WordPress Plugin Social Media Tab Remote Code Execution (1.0.9)
WordPress Plugin Image Export Arbitrary File Download (1.1.0)