PT-2016-2329 · Vmware · Vsphere Web Client+2

Publicado

2016-07-03

·

Atualizado

2017-09-01

·

CVE-2015-6931

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions VMware vCenter Server versions 5.0 before U3g VMware vCenter Server versions 5.1 before U3d VMware vCenter Server versions 5.5 before U2d
Description The issue is related to a cross-site scripting (XSS) vulnerability in the vSphere Web Client component. This vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted URL, potentially enabling them to execute malicious code on the client-side. The vulnerability exists due to insufficient protection of the web page structure.
Recommendations For versions 5.0 before U3g, update to U3g or later to resolve the issue. For versions 5.1 before U3d, update to U3d or later to resolve the issue. For versions 5.5 before U2d, update to U2d or later to resolve the issue.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-01718
CVE-2015-6931

Produtos afetados

Vmware Vcenter
Vmware Vcenter Server
Vsphere Web Client