<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0">
  <channel>
    <title>VMSA-2022-0008</title>
    <language>en-US</language>
    <pubDate>Wed, 27 Sep 2023 3:42:8 PDT</pubDate>
    <lastBuildDate>Wed, 27 Sep 2023 3:42:8 PDT</lastBuildDate>
    <link>https://www.vmware.com/security/advisories/VMSA-2022-0008.html</link>
    <sy:updatePeriod>hourly</sy:updatePeriod>
    <sy:updateFrequency>1</sy:updateFrequency>
    <item>
      <title>VMSA-2022-0008</title>
      <pubDate>Wed, 27 Sep 2023 3:42:8 PDT</pubDate>
      <description>
        <![CDATA[<div class="aem-Grid aem-Grid--12 aem-Grid--default--12 "> 
 <div class="responsivegrid aem-GridColumn aem-GridColumn--default--12"> 
  <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 "> 
   <div class="advisories-summary aem-GridColumn aem-GridColumn--default--12"> 
    <link rel="stylesheet" href="/etc.clientlibs/vmware-modernize-cms/componentlibrary/components/content/advisories-summary/clientlibs.min.css" type="text/css">  
    <section class="sa-detail-wrapper section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <div class="sa-image-block"> 
          <div class="sa-severity"> 
           <div class="sa-critical"> 
            <p>Critical</p> 
           </div> 
          </div> 
         </div> 
         <div class="sa-detail-block"> 
          <div class="col-md-8"> 
           <div class="sa-details"> 
            <div class="sa-row-group"> 
             <label>Advisory ID:</label> 
             <span>VMSA-2022-0008</span> 
            </div> 
            <div class="sa-row-group"> 
             <label>CVSSv3 Range:</label> 
             <span>9.1</span> 
            </div> 
            <div class="sa-row-group"> 
             <label>Issue Date:</label> 
             <span>2022-03-23</span> 
            </div> 
            <div class="sa-row-group"> 
             <label>Updated On:</label> 
             <span>2022-03-23 (Initial Advisory)</span> 
            </div> 
            <div class="sa-row-group"> 
             <label>CVE(s):</label> 
             <span>CVE-2022-22951, CVE-2022-22952</span> 
            </div> 
            <div class="sa-row-group"> 
             <label>Synopsis:</label> 
             <span>VMware Carbon Black App Control update addresses multiple vulnerabilities (CVE-2022-22951, CVE-2022-22952)</span> 
            </div> 
           </div> 
          </div> 
          <div class="col-md-4 sa-summary-link-section" data-html2canvas-ignore="true">  
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <link rel="stylesheet" href="/etc.clientlibs/vmware-modernize-cms/componentlibrary/components/content/secadvheading/clientlibs.min.css" type="text/css"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>1. Impacted Products</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <ul> 
             <li>VMware Carbon Black App Control (AppC)</li> 
            </ul> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>2. Introduction</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>Multiple&nbsp;vulnerabilities&nbsp;in&nbsp;VMware Carbon Black App Control&nbsp;were privately reported to VMware. Updates are available to remediate these vulnerabilities in affected VMware products.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>3a. OS command injection vulnerability in VMware Carbon Black App Control (CVE-2022-22951)</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Description</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware Carbon Black App Control&nbsp;contains an&nbsp;OS command injection&nbsp;vulnerability. VMware has evaluated the severity of this issue to be in the&nbsp;<a href="https://www.vmware.com/support/policies/security_response.html">Critical severity range</a>&nbsp;with a maximum CVSSv3 base score of&nbsp;<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H">9.1</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Known Attack Vectors</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>An authenticated, high privileged&nbsp;malicious&nbsp;actor with network access to the&nbsp;VMware App Control administration interface&nbsp;may be able to execute commands on the server due to improper input validation leading to remote code execution.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Resolution</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>To remediate&nbsp;CVE-2022-22951&nbsp;apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found below.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Workarounds</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Additional Documentation</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Notes</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>Before using the download links make sure to log into the Carbon Black User Exchange (UEX).<br> </p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Acknowledgements</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware would like to thank&nbsp;Jari Jääskelä (@JJaaskela)&nbsp;for reporting this issue to us.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>3b. File upload vulnerability in VMware Carbon Black App Control (CVE-2022-22952)</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Description</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware Carbon Black App Control&nbsp;contains a file upload vulnerability. VMware has evaluated the severity of this issue to be in the&nbsp;<a href="https://www.vmware.com/support/policies/security_response.html">Critical severity range</a>&nbsp;with a maximum CVSSv3 base score of&nbsp;<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H">9.1</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Known Attack Vectors</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>A malicious actor with administrative access to the VMware App Control administration interface may be able to execute code on the Windows instance where AppC Server is installed by uploading a specially crafted file.<br> </p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Resolution</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>To remediate&nbsp;CVE-2022-22952&nbsp;apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found below.<br> </p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Workarounds</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Additional Documentation</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Notes</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>Before using the download links make sure to log into the Carbon Black User Exchange (UEX).<br> </p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Acknowledgements</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware would like to thank&nbsp;Jari Jääskelä (@JJaaskela)&nbsp;for reporting this issue to us.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Response Matrix 3a, 3b</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="advisories-data aem-GridColumn aem-GridColumn--default--12"> 
    <link rel="stylesheet" href="/etc.clientlibs/vmware-modernize-cms/componentlibrary/components/content/advisories-data/clientlibs.min.css" type="text/css"> 
    <section class="response-matrix"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <div class="section-custom"> 
          <div class="table-responsive"> 
           <table class="table"> 
            <tbody>
             <tr class="tr thead"> 
              <td class="td">Product</td> 
              <td class="td">Version</td> 
              <td class="td">Running On</td> 
              <td class="td">CVE Identifier</td> 
              <td class="td">CVSSv3</td> 
              <td class="td">Severity</td> 
              <td class="td">Fixed Version</td> 
              <td class="td">Workarounds</td> 
              <td class="td">Additional Documentation</td> 
             </tr> 
             <tr class="tr"> 
              <td class="td" data-th="Product"> 
               <div class="td-content">
                AppC 
               </div> </td> 
              <td class="td" data-th="Version"> 
               <div class="td-content">
                8.8.x
               </div> </td> 
              <td class="td" data-th="Running On"> 
               <div class="td-content">
                Windows
               </div> </td> 
              <td class="td" data-th="CVE Identifier"> 
               <div class="td-content">
                CVE-2022-22951, CVE-2022-22952
               </div> </td> 
              <td class="td" data-th="CVSSV3"> 
               <div class="td-content">
                <a aria-label="9.1" href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H">9.1</a>
               </div> </td> 
              <td class="td" data-th="Severity"> 
               <div class="td-content"> 
                <div class="sa-severity-blk">
                 critical
                </div> 
                <span class="sa-severity sa-critical"></span> 
               </div> </td> 
              <td class="td" data-th="Fixed Version"> 
               <div class="td-content">
                <a aria-label="8.8.2" href="https://community.carbonblack.com/t5/Documentation-Downloads/Critical-App-Control-Server-Patch-Announcement-3-23-22/ta-p/111804#M3557">8.8.2</a>
               </div> </td> 
              <td class="td" data-th="Workarounds"> 
               <div class="td-content">
                None
               </div> </td> 
              <td class="td" data-th="Additional Documents"> 
               <div class="td-content">
                None
               </div> </td> 
             </tr> 
             <tr class="tr"> 
              <td class="td" data-th="Product"> 
               <div class="td-content">
                AppC 
               </div> </td> 
              <td class="td" data-th="Version"> 
               <div class="td-content">
                8.7.x
               </div> </td> 
              <td class="td" data-th="Running On"> 
               <div class="td-content">
                Windows
               </div> </td> 
              <td class="td" data-th="CVE Identifier"> 
               <div class="td-content">
                CVE-2022-22951, CVE-2022-22952
               </div> </td> 
              <td class="td" data-th="CVSSV3"> 
               <div class="td-content">
                <a aria-label="9.1" href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H">9.1</a>
               </div> </td> 
              <td class="td" data-th="Severity"> 
               <div class="td-content"> 
                <div class="sa-severity-blk">
                 critical
                </div> 
                <span class="sa-severity sa-critical"></span> 
               </div> </td> 
              <td class="td" data-th="Fixed Version"> 
               <div class="td-content">
                <a aria-label="8.7.4" href="https://community.carbonblack.com/t5/Documentation-Downloads/Critical-App-Control-Server-Patch-Announcement-3-23-22/ta-p/111804#M3557">8.7.4</a>
               </div> </td> 
              <td class="td" data-th="Workarounds"> 
               <div class="td-content">
                None
               </div> </td> 
              <td class="td" data-th="Additional Documents"> 
               <div class="td-content">
                None
               </div> </td> 
             </tr> 
             <tr class="tr"> 
              <td class="td" data-th="Product"> 
               <div class="td-content">
                AppC 
               </div> </td> 
              <td class="td" data-th="Version"> 
               <div class="td-content">
                8.6.x
               </div> </td> 
              <td class="td" data-th="Running On"> 
               <div class="td-content">
                Windows
               </div> </td> 
              <td class="td" data-th="CVE Identifier"> 
               <div class="td-content">
                CVE-2022-22951, CVE-2022-22952
               </div> </td> 
              <td class="td" data-th="CVSSV3"> 
               <div class="td-content">
                <a aria-label="9.1" href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H">9.1</a>
               </div> </td> 
              <td class="td" data-th="Severity"> 
               <div class="td-content"> 
                <div class="sa-severity-blk">
                 critical
                </div> 
                <span class="sa-severity sa-critical"></span> 
               </div> </td> 
              <td class="td" data-th="Fixed Version"> 
               <div class="td-content">
                <a aria-label="8.6.6" href="https://community.carbonblack.com/t5/Documentation-Downloads/Critical-App-Control-Server-Patch-Announcement-3-23-22/ta-p/111804#M3557">8.6.6</a>
               </div> </td> 
              <td class="td" data-th="Workarounds"> 
               <div class="td-content">
                None
               </div> </td> 
              <td class="td" data-th="Additional Documents"> 
               <div class="td-content">
                None
               </div> </td> 
             </tr> 
             <tr class="tr"> 
              <td class="td" data-th="Product"> 
               <div class="td-content">
                AppC 
               </div> </td> 
              <td class="td" data-th="Version"> 
               <div class="td-content">
                8.5.x
               </div> </td> 
              <td class="td" data-th="Running On"> 
               <div class="td-content">
                Windows
               </div> </td> 
              <td class="td" data-th="CVE Identifier"> 
               <div class="td-content">
                CVE-2022-22951, CVE-2022-22952
               </div> </td> 
              <td class="td" data-th="CVSSV3"> 
               <div class="td-content">
                <a aria-label="9.1" href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H">9.1</a>
               </div> </td> 
              <td class="td" data-th="Severity"> 
               <div class="td-content"> 
                <div class="sa-severity-blk">
                 critical
                </div> 
                <span class="sa-severity sa-critical"></span> 
               </div> </td> 
              <td class="td" data-th="Fixed Version"> 
               <div class="td-content">
                <a aria-label="8.5.14" href="https://community.carbonblack.com/t5/Documentation-Downloads/Critical-App-Control-Server-Patch-Announcement-3-23-22/ta-p/111804#M3557">8.5.14</a>
               </div> </td> 
              <td class="td" data-th="Workarounds"> 
               <div class="td-content">
                None
               </div> </td> 
              <td class="td" data-th="Additional Documents"> 
               <div class="td-content">
                None
               </div> </td> 
             </tr> 
            </tbody>
           </table> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>4. References</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>Fixed Version(s) and Release Notes:</p> 
            <p>VMware Carbon Black App Control 8.8.2, 8.7.4, 8.6.6, 8.5.14</p> 
            <p>Downloads and Documentation:</p> 
            <p><a href="https://community.carbonblack.com/t5/Documentation-Downloads/Critical-App-Control-Server-Patch-Announcement-3-23-22/ta-p/111804#M3557">https://community.carbonblack.com/t5/Documentation-Downloads/Critical-App-Control-Server-Patch-Announcement-3-23-22/ta-p/111804#M3557</a><br> </p> 
            <p>&nbsp;</p> 
            <p>Mitre CVE Dictionary Links:</p> 
            <p><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22951">https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22951</a></p> 
            <p><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22952">https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22952</a></p> 
            <p>&nbsp;</p> 
            <p>FIRST CVSSv3 Calculator:<br> CVE-2022-22951:&nbsp;<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H">https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</a></p> 
            <p>CVE-2022-22952:&nbsp;<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H">https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</a></p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>5. Change Log</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>2022-03-23&nbsp;VMSA-2022-0008<br> Initial security advisory.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>6. Contact</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>E-mail list for product security notifications and announcements:</p> 
            <p><a href="https://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce">https://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>This Security Advisory is posted to the following lists:&nbsp;&nbsp;</p> 
            <p><a href="mailto:security-announce@lists.vmware.com">security-announce@lists.vmware.com&nbsp;&nbsp;</a></p> 
            <p><a href="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com&nbsp;&nbsp;</a></p> 
            <p><a href="mailto:fulldisclosure@seclists.org">fulldisclosure@seclists.org&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>E-mail: <a href="mailto:security@vmware.com">security@vmware.com</a></p> 
            <p>PGP key at:</p> 
            <p><a href="https://kb.vmware.com/kb/1055">https://kb.vmware.com/kb/1055&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>VMware Security Advisories</p> 
            <p><a href="https://www.vmware.com/security/advisories">https://www.vmware.com/security/advisories&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>VMware Security Response Policy</p> 
            <p><a href="https://www.vmware.com/support/policies/security_response.html">https://www.vmware.com/support/policies/security_response.html&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>VMware Lifecycle Support Phases</p> 
            <p><a href="https://www.vmware.com/support/policies/lifecycle.html">https://www.vmware.com/support/policies/lifecycle.html&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>VMware Security &amp; Compliance Blog&nbsp;&nbsp;</p> 
            <p><a href="https://blogs.vmware.com/security">https://blogs.vmware.com/security&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>Twitter</p> 
            <p><a href="https://twitter.com/VMwareSRC">https://twitter.com/VMwareSRC<br> </a></p> 
            <p>&nbsp;</p> 
            <p>Copyright 2022 VMware Inc. All rights reserved.<br> &nbsp;<br> </p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
  </div> 
 </div> 
</div>]]>
      </description>
      <content:encoded>
        <![CDATA[<div class="aem-Grid aem-Grid--12 aem-Grid--default--12 "> 
 <div class="responsivegrid aem-GridColumn aem-GridColumn--default--12"> 
  <div class="aem-Grid aem-Grid--12 aem-Grid--default--12 "> 
   <div class="advisories-summary aem-GridColumn aem-GridColumn--default--12"> 
    <link rel="stylesheet" href="/etc.clientlibs/vmware-modernize-cms/componentlibrary/components/content/advisories-summary/clientlibs.min.css" type="text/css">  
    <section class="sa-detail-wrapper section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <div class="sa-image-block"> 
          <div class="sa-severity"> 
           <div class="sa-critical"> 
            <p>Critical</p> 
           </div> 
          </div> 
         </div> 
         <div class="sa-detail-block"> 
          <div class="col-md-8"> 
           <div class="sa-details"> 
            <div class="sa-row-group"> 
             <label>Advisory ID:</label> 
             <span>VMSA-2022-0008</span> 
            </div> 
            <div class="sa-row-group"> 
             <label>CVSSv3 Range:</label> 
             <span>9.1</span> 
            </div> 
            <div class="sa-row-group"> 
             <label>Issue Date:</label> 
             <span>2022-03-23</span> 
            </div> 
            <div class="sa-row-group"> 
             <label>Updated On:</label> 
             <span>2022-03-23 (Initial Advisory)</span> 
            </div> 
            <div class="sa-row-group"> 
             <label>CVE(s):</label> 
             <span>CVE-2022-22951, CVE-2022-22952</span> 
            </div> 
            <div class="sa-row-group"> 
             <label>Synopsis:</label> 
             <span>VMware Carbon Black App Control update addresses multiple vulnerabilities (CVE-2022-22951, CVE-2022-22952)</span> 
            </div> 
           </div> 
          </div> 
          <div class="col-md-4 sa-summary-link-section" data-html2canvas-ignore="true">  
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <link rel="stylesheet" href="/etc.clientlibs/vmware-modernize-cms/componentlibrary/components/content/secadvheading/clientlibs.min.css" type="text/css"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>1. Impacted Products</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <ul> 
             <li>VMware Carbon Black App Control (AppC)</li> 
            </ul> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>2. Introduction</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>Multiple&nbsp;vulnerabilities&nbsp;in&nbsp;VMware Carbon Black App Control&nbsp;were privately reported to VMware. Updates are available to remediate these vulnerabilities in affected VMware products.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>3a. OS command injection vulnerability in VMware Carbon Black App Control (CVE-2022-22951)</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Description</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware Carbon Black App Control&nbsp;contains an&nbsp;OS command injection&nbsp;vulnerability. VMware has evaluated the severity of this issue to be in the&nbsp;<a href="https://www.vmware.com/support/policies/security_response.html">Critical severity range</a>&nbsp;with a maximum CVSSv3 base score of&nbsp;<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H">9.1</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Known Attack Vectors</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>An authenticated, high privileged&nbsp;malicious&nbsp;actor with network access to the&nbsp;VMware App Control administration interface&nbsp;may be able to execute commands on the server due to improper input validation leading to remote code execution.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Resolution</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>To remediate&nbsp;CVE-2022-22951&nbsp;apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found below.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Workarounds</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Additional Documentation</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Notes</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>Before using the download links make sure to log into the Carbon Black User Exchange (UEX).<br> </p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Acknowledgements</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware would like to thank&nbsp;Jari Jääskelä (@JJaaskela)&nbsp;for reporting this issue to us.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>3b. File upload vulnerability in VMware Carbon Black App Control (CVE-2022-22952)</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Description</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware Carbon Black App Control&nbsp;contains a file upload vulnerability. VMware has evaluated the severity of this issue to be in the&nbsp;<a href="https://www.vmware.com/support/policies/security_response.html">Critical severity range</a>&nbsp;with a maximum CVSSv3 base score of&nbsp;<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H">9.1</a>.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Known Attack Vectors</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>A malicious actor with administrative access to the VMware App Control administration interface may be able to execute code on the Windows instance where AppC Server is installed by uploading a specially crafted file.<br> </p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Resolution</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>To remediate&nbsp;CVE-2022-22952&nbsp;apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found below.<br> </p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Workarounds</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Additional Documentation</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>None.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Notes</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>Before using the download links make sure to log into the Carbon Black User Exchange (UEX).<br> </p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Acknowledgements</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>VMware would like to thank&nbsp;Jari Jääskelä (@JJaaskela)&nbsp;for reporting this issue to us.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <p class="mt-15"><b>Response Matrix 3a, 3b</b></p> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="advisories-data aem-GridColumn aem-GridColumn--default--12"> 
    <link rel="stylesheet" href="/etc.clientlibs/vmware-modernize-cms/componentlibrary/components/content/advisories-data/clientlibs.min.css" type="text/css"> 
    <section class="response-matrix"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <div class="section-custom"> 
          <div class="table-responsive"> 
           <table class="table"> 
            <tbody>
             <tr class="tr thead"> 
              <td class="td">Product</td> 
              <td class="td">Version</td> 
              <td class="td">Running On</td> 
              <td class="td">CVE Identifier</td> 
              <td class="td">CVSSv3</td> 
              <td class="td">Severity</td> 
              <td class="td">Fixed Version</td> 
              <td class="td">Workarounds</td> 
              <td class="td">Additional Documentation</td> 
             </tr> 
             <tr class="tr"> 
              <td class="td" data-th="Product"> 
               <div class="td-content">
                AppC 
               </div> </td> 
              <td class="td" data-th="Version"> 
               <div class="td-content">
                8.8.x
               </div> </td> 
              <td class="td" data-th="Running On"> 
               <div class="td-content">
                Windows
               </div> </td> 
              <td class="td" data-th="CVE Identifier"> 
               <div class="td-content">
                CVE-2022-22951, CVE-2022-22952
               </div> </td> 
              <td class="td" data-th="CVSSV3"> 
               <div class="td-content">
                <a aria-label="9.1" href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H">9.1</a>
               </div> </td> 
              <td class="td" data-th="Severity"> 
               <div class="td-content"> 
                <div class="sa-severity-blk">
                 critical
                </div> 
                <span class="sa-severity sa-critical"></span> 
               </div> </td> 
              <td class="td" data-th="Fixed Version"> 
               <div class="td-content">
                <a aria-label="8.8.2" href="https://community.carbonblack.com/t5/Documentation-Downloads/Critical-App-Control-Server-Patch-Announcement-3-23-22/ta-p/111804#M3557">8.8.2</a>
               </div> </td> 
              <td class="td" data-th="Workarounds"> 
               <div class="td-content">
                None
               </div> </td> 
              <td class="td" data-th="Additional Documents"> 
               <div class="td-content">
                None
               </div> </td> 
             </tr> 
             <tr class="tr"> 
              <td class="td" data-th="Product"> 
               <div class="td-content">
                AppC 
               </div> </td> 
              <td class="td" data-th="Version"> 
               <div class="td-content">
                8.7.x
               </div> </td> 
              <td class="td" data-th="Running On"> 
               <div class="td-content">
                Windows
               </div> </td> 
              <td class="td" data-th="CVE Identifier"> 
               <div class="td-content">
                CVE-2022-22951, CVE-2022-22952
               </div> </td> 
              <td class="td" data-th="CVSSV3"> 
               <div class="td-content">
                <a aria-label="9.1" href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H">9.1</a>
               </div> </td> 
              <td class="td" data-th="Severity"> 
               <div class="td-content"> 
                <div class="sa-severity-blk">
                 critical
                </div> 
                <span class="sa-severity sa-critical"></span> 
               </div> </td> 
              <td class="td" data-th="Fixed Version"> 
               <div class="td-content">
                <a aria-label="8.7.4" href="https://community.carbonblack.com/t5/Documentation-Downloads/Critical-App-Control-Server-Patch-Announcement-3-23-22/ta-p/111804#M3557">8.7.4</a>
               </div> </td> 
              <td class="td" data-th="Workarounds"> 
               <div class="td-content">
                None
               </div> </td> 
              <td class="td" data-th="Additional Documents"> 
               <div class="td-content">
                None
               </div> </td> 
             </tr> 
             <tr class="tr"> 
              <td class="td" data-th="Product"> 
               <div class="td-content">
                AppC 
               </div> </td> 
              <td class="td" data-th="Version"> 
               <div class="td-content">
                8.6.x
               </div> </td> 
              <td class="td" data-th="Running On"> 
               <div class="td-content">
                Windows
               </div> </td> 
              <td class="td" data-th="CVE Identifier"> 
               <div class="td-content">
                CVE-2022-22951, CVE-2022-22952
               </div> </td> 
              <td class="td" data-th="CVSSV3"> 
               <div class="td-content">
                <a aria-label="9.1" href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H">9.1</a>
               </div> </td> 
              <td class="td" data-th="Severity"> 
               <div class="td-content"> 
                <div class="sa-severity-blk">
                 critical
                </div> 
                <span class="sa-severity sa-critical"></span> 
               </div> </td> 
              <td class="td" data-th="Fixed Version"> 
               <div class="td-content">
                <a aria-label="8.6.6" href="https://community.carbonblack.com/t5/Documentation-Downloads/Critical-App-Control-Server-Patch-Announcement-3-23-22/ta-p/111804#M3557">8.6.6</a>
               </div> </td> 
              <td class="td" data-th="Workarounds"> 
               <div class="td-content">
                None
               </div> </td> 
              <td class="td" data-th="Additional Documents"> 
               <div class="td-content">
                None
               </div> </td> 
             </tr> 
             <tr class="tr"> 
              <td class="td" data-th="Product"> 
               <div class="td-content">
                AppC 
               </div> </td> 
              <td class="td" data-th="Version"> 
               <div class="td-content">
                8.5.x
               </div> </td> 
              <td class="td" data-th="Running On"> 
               <div class="td-content">
                Windows
               </div> </td> 
              <td class="td" data-th="CVE Identifier"> 
               <div class="td-content">
                CVE-2022-22951, CVE-2022-22952
               </div> </td> 
              <td class="td" data-th="CVSSV3"> 
               <div class="td-content">
                <a aria-label="9.1" href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H">9.1</a>
               </div> </td> 
              <td class="td" data-th="Severity"> 
               <div class="td-content"> 
                <div class="sa-severity-blk">
                 critical
                </div> 
                <span class="sa-severity sa-critical"></span> 
               </div> </td> 
              <td class="td" data-th="Fixed Version"> 
               <div class="td-content">
                <a aria-label="8.5.14" href="https://community.carbonblack.com/t5/Documentation-Downloads/Critical-App-Control-Server-Patch-Announcement-3-23-22/ta-p/111804#M3557">8.5.14</a>
               </div> </td> 
              <td class="td" data-th="Workarounds"> 
               <div class="td-content">
                None
               </div> </td> 
              <td class="td" data-th="Additional Documents"> 
               <div class="td-content">
                None
               </div> </td> 
             </tr> 
            </tbody>
           </table> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>4. References</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>Fixed Version(s) and Release Notes:</p> 
            <p>VMware Carbon Black App Control 8.8.2, 8.7.4, 8.6.6, 8.5.14</p> 
            <p>Downloads and Documentation:</p> 
            <p><a href="https://community.carbonblack.com/t5/Documentation-Downloads/Critical-App-Control-Server-Patch-Announcement-3-23-22/ta-p/111804#M3557">https://community.carbonblack.com/t5/Documentation-Downloads/Critical-App-Control-Server-Patch-Announcement-3-23-22/ta-p/111804#M3557</a><br> </p> 
            <p>&nbsp;</p> 
            <p>Mitre CVE Dictionary Links:</p> 
            <p><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22951">https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22951</a></p> 
            <p><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22952">https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22952</a></p> 
            <p>&nbsp;</p> 
            <p>FIRST CVSSv3 Calculator:<br> CVE-2022-22951:&nbsp;<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H">https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</a></p> 
            <p>CVE-2022-22952:&nbsp;<a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H">https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</a></p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>5. Change Log</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>2022-03-23&nbsp;VMSA-2022-0008<br> Initial security advisory.</p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
   <div class="secadvheading aem-GridColumn aem-GridColumn--default--12"> 
    <section class="section-custom"> 
     <div class="container"> 
      <div class="content"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <h5 class="mt-30"><b>6. Contact</b></h5> 
        </div> 
       </div> 
      </div> 
     </div> 
    </section>
   </div> 
   <div class="text aem-GridColumn aem-GridColumn--default--12"> 
    <div class="cmp-text     "> 
     <div class="nested-filtered-table active"> 
      <div class="container"> 
       <div class="row"> 
        <div class="col-md-12"> 
         <input type="hidden" class="ExpandLabel"> 
         <input type="hidden" class="CollapseLabel"> 
         <input type="hidden" class="BrightcoveAccountID"> 
         <div class="container text-container" data-aos="fade-up" data-aos-delay="500"> 
          <div class="row"> 
           <div class="col-md-12 no-padd " data-aos="fade-up" data-aos-delay="500"> 
            <p>E-mail list for product security notifications and announcements:</p> 
            <p><a href="https://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce">https://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>This Security Advisory is posted to the following lists:&nbsp;&nbsp;</p> 
            <p><a href="mailto:security-announce@lists.vmware.com">security-announce@lists.vmware.com&nbsp;&nbsp;</a></p> 
            <p><a href="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com&nbsp;&nbsp;</a></p> 
            <p><a href="mailto:fulldisclosure@seclists.org">fulldisclosure@seclists.org&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>E-mail: <a href="mailto:security@vmware.com">security@vmware.com</a></p> 
            <p>PGP key at:</p> 
            <p><a href="https://kb.vmware.com/kb/1055">https://kb.vmware.com/kb/1055&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>VMware Security Advisories</p> 
            <p><a href="https://www.vmware.com/security/advisories">https://www.vmware.com/security/advisories&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>VMware Security Response Policy</p> 
            <p><a href="https://www.vmware.com/support/policies/security_response.html">https://www.vmware.com/support/policies/security_response.html&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>VMware Lifecycle Support Phases</p> 
            <p><a href="https://www.vmware.com/support/policies/lifecycle.html">https://www.vmware.com/support/policies/lifecycle.html&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>VMware Security &amp; Compliance Blog&nbsp;&nbsp;</p> 
            <p><a href="https://blogs.vmware.com/security">https://blogs.vmware.com/security&nbsp;</a></p> 
            <p>&nbsp;</p> 
            <p>Twitter</p> 
            <p><a href="https://twitter.com/VMwareSRC">https://twitter.com/VMwareSRC<br> </a></p> 
            <p>&nbsp;</p> 
            <p>Copyright 2022 VMware Inc. All rights reserved.<br> &nbsp;<br> </p> 
           </div> 
          </div> 
         </div> 
        </div> 
       </div> 
      </div> 
     </div> 
    </div> 
   </div> 
  </div> 
 </div> 
</div>]]>
      </content:encoded>
      <link>https://www.vmware.com/security/advisories/VMSA-2022-0008.html</link>
    </item>
  </channel>
</rss>
