CVE for SDDC Manager appliance
search cancel

CVE for SDDC Manager appliance

book

Article ID: 313193

calendar_today

Updated On:

Products

VMware Cloud Foundation

Issue/Introduction

Applicability of the above CVE for SDDC Manager appliance.


Symptoms:

Security scan reveals that the SDDC Manager appliance is vulnerable to following CVE:
CVE-2023-32002, CVE-2023-32003, CVE-2023-32004, CVE-2023-32005, CVE-2023-32006, CVE-2023-32558, CVE-2023-32559.


Cause

Using specific version node.js in SDDC Manager appliance versions 5.0 and below.

Resolution

To resolve the issuse, please upgrade VCF version to 5.0.0.1 and 5.1.0 (Not needed because SDDC Manager is not affected).

All the above CVE affects only experimental features (permission model and policy mechanism) of node.js which is not being used.