FAIL › dossier
VMware Tanzu
VENDOR· dossier confidence 20%
VMware Tanzu delivers container orchestration but carries a history of critical RCE vulnerabilities in Spring-based components, including CVE-2018-1273 actively exploited in ransomware attacks.
PROFILE
CategoryvendorWhat they doVMware Tanzu provides container orchestration and Kubernetes management solutions for enterprise and cloud-native workloads.
Websitehttps://www.vmware.com ↗
SECURITY POSTURE
History of critical RCE vulnerabilities in Tanzu Spring components, including CVE-2018-1273 actively exploited in ransomware attacks.
Notable failures
- CVE-2018-1273 critical RCE in Spring Data Commons exploited in ransomware
- CVE-2022-22963 high RCE in Spring Cloud Function routing
- CVE-2020-5410 high path traversal in Cloud Config
Patterns: Spring-based Tanzu components with RCE vulnerabilities; Configuration management vulnerabilities in Spring Cloud
FAILURE HISTORY · 3
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-03-25 | CVE-2018-1273 | critical | VMware Tanzu Spring Data Commons contained a remote code execution vulnerability actively exploited in ransomware attacks, impacting DIB organizations using this software stack. |
| 2022-08-25 | CVE-2022-22963 | high | VMware Tanzu Spring Cloud Function RCE |
| 2022-03-25 | CVE-2020-5410 | high | A path traversal flaw in VMware Tanzu Spring Cloud Config allowed attackers to serve arbitrary files, leading to potential data exposure and compliance violations. |
DOSSIER SOURCES
- Vmware CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
- CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
- Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find · www.cvefind.com
Open questions: Current remediation status of CVE-2018-1273 · Frequency of patching for Spring-based components
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-31 03:59:08.321035+00:00