The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in remote code execution.
id: CVE-2022-31704
info:
name: VMware vRealize Log Insight - Improper Access Control to RCE
aut
...