PT-2015-3312 · Vmware · Vmware Vsphere Client+3
Andrey Evlanin
+4
·
Publicado
2015-10-23
·
Atualizado
2017-07-28
·
CVE-2016-7458
CVSS v3.1
5.8
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
VMware vSphere Client versions 5.5 before U3e
VMware vSphere Client versions 6.0 before U2a
Description
The issue is related to an XML External Entity (XXE) problem, where an XML document containing an external entity declaration in conjunction with an entity reference can be used to read arbitrary files. This is due to incorrect restriction of XML links to external objects. Exploitation of the issue may allow a remote attacker to access confidential information by convincing a user to connect to a malicious vCenter or ESXi server.
Recommendations
For versions 5.5 before U3e, update to U3e or later to resolve the issue.
For versions 6.0 before U2a, update to U2a or later to resolve the issue.
As a temporary workaround, consider restricting access to the vCenter and ESXi servers to minimize the risk of exploitation.
Correção
XXE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Esxi
Vmware Vcenter
Vmware Vsphere Client
Vcenter