Description
Due to vulnerabilities in Log4j library used by vCenter, an unauthenticated attacker can leak sensitive information or execute arbitrary code on the system.
Remediation
Upgrade to the latest version of VMware Horizon
References
Related Vulnerabilities
WordPress Plugin WP Super Cache PHP Code Injection (1.2)
Server-side JavaScript injection
WordPress Plugin Theme Editor Arbitrary File Download (2.5)
RCE in Ivanti Connect Secure and Policy Secure (CVE-2024-21887)
WordPress Plugin Subscribe to Comments Unsubscribe Challenge Information Disclosure (2.0.2)