Description
Due to vulnerabilities in Log4j library used by vCenter, an unauthenticated attacker can leak sensitive information or execute arbitrary code on the system.
Remediation
Upgrade to the latest version of VMware Horizon
References
Related Vulnerabilities
Sonicwall SMA 100 Unintended proxy (CVE-2021-20042)
GeoServer WMS SSRF (CVE-2023-43795)
Oracle E-Business Suite SSRF (CVE-2018-3167)
WordPress Plugin Video Conferencing with Zoom Information Disclosure (3.8.16)
WordPress Plugin ProfileGrid-User Profiles, Groups and Communities Remote Code Execution (2.8.5)