Description
Due to vulnerabilities in Log4j library used by vCenter, an unauthenticated attacker can leak sensitive information or execute arbitrary code on the system.
Remediation
Upgrade to the latest version of VMware Horizon
References
Related Vulnerabilities
Joomla! JomSocial remote code execution
SAP IGS XXE (CVE-2018-2392, CVE-2018-2393)
Oracle Sun GlassFish/Java System Application Server Remote Authentication Bypass Vulnerability
ColdFusion FlashGateway Deserialization RCE CVE-2019-7091
WordPress Plugin Page Flip Image Gallery 'book_id' Parameter Remote File Disclosure (0.2.2)