PT-2015-3312 · Vmware · Vmware Vsphere Client+3

Andrey Evlanin

+4

·

Publicado

2015-10-23

·

Atualizado

2017-07-28

·

CVE-2016-7458

CVSS v3.1

5.8

Média

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions VMware vSphere Client versions 5.5 before U3e VMware vSphere Client versions 6.0 before U2a
Description The issue is related to an XML External Entity (XXE) problem, where an XML document containing an external entity declaration in conjunction with an entity reference can be used to read arbitrary files. This is due to incorrect restriction of XML links to external objects. Exploitation of the issue may allow a remote attacker to access confidential information by convincing a user to connect to a malicious vCenter or ESXi server.
Recommendations For versions 5.5 before U3e, update to U3e or later to resolve the issue. For versions 6.0 before U2a, update to U2a or later to resolve the issue. As a temporary workaround, consider restricting access to the vCenter and ESXi servers to minimize the risk of exploitation.

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02205
CVE-2016-7458

Produtos afetados

Esxi
Vmware Vcenter
Vmware Vsphere Client
Vcenter