Description
Due to vulnerabilities in Log4j library used by vCenter, an unauthenticated attacker can leak sensitive information or execute arbitrary code on the system.
Remediation
Upgrade to the latest version of VMware Horizon
References
Related Vulnerabilities
WordPress Plugin Fusion Engage Local File Disclosure (1.0.5)
XML external entity injection (variant)
Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (CVE-2024-6387)
vBulletin 5 CONNECT remote code execution
WordPress Plugin MiwoFTP-File & Folder Manager Arbitrary File Disclosure (1.0.4)