CVE-2022-22951
Dashboard / Vulnerabilities / CVE-2022-22951
CVE-2022-22951
Published: 23 Mar 2022Last Modified: 13 Feb 2026
Summary:
Details: VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious actor with network access to the VMware App Control administration interface may be able to execute commands on the server due to improper input validation leading to remote code execution.
References: https://www.vmware.com/security/advisories/VMSA-2022-0008.html, https://www.vmware.com/security/advisories/VMSA-2022-0008.html
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 6abd24ef0514e93b714c3d138efc99c8e64159db
Affected versions
v8.6.0
v8.6.1
v8.6.2
v8.6.3
v8.6.4
v8.6.5
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
