VMware Releases Critical Security Update
Security update for Tanzu Application Service for VMs, Tanzu Operations Manager, and TKGI
Summary
Security update for Tanzu Application Service for VMs, Tanzu Operations Manager, and TKGI
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
VMware has released a security update to address the critical Spring Framework remote code execution (RCE) vulnerability known as CVE-2022-22965, which affects Tanzu Applications Service for VMs, Tanzu Operations Manager, and TKGI. A remote attacker could exploit this vulnerability to take control of an affected system.
Remediation advice
Affected organisations are encouraged to review VMware Security Advisory VMSA-2022-0010 and apply the necessary update.
Definitive source of threat updates
Last edited: 5 April 2022 3:00 pm