High
CVE-2022-31702 CVSS:9.8
VMware vRealize Network Insight could allow a remote attacker to execute arbitrary commands on the system, caused by a command injection vulnerability in the vRNI REST API. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
CVE-2022-31703 CVSS:7.5
VMware vRealize Network Insight could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing “dot dot” sequences (/../) to view arbitrary files on the system.
VMWare
Refer to VMware Security Advisory for patch, upgrade or suggested workaround information.