PT-2015-3312 · Vmware · Vmware Vsphere Client+3

Andrey Evlanin

+4

·

Published

2015-10-23

·

Updated

2017-07-28

·

CVE-2016-7458

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions VMware vSphere Client versions 5.5 before U3e VMware vSphere Client versions 6.0 before U2a
Description The issue is related to an XML External Entity (XXE) problem, where an XML document containing an external entity declaration in conjunction with an entity reference can be used to read arbitrary files. This is due to incorrect restriction of XML links to external objects. Exploitation of the issue may allow a remote attacker to access confidential information by convincing a user to connect to a malicious vCenter or ESXi server.
Recommendations For versions 5.5 before U3e, update to U3e or later to resolve the issue. For versions 6.0 before U2a, update to U2a or later to resolve the issue. As a temporary workaround, consider restricting access to the vCenter and ESXi servers to minimize the risk of exploitation.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02205
CVE-2016-7458

Affected Products

Esxi
Vmware Vcenter
Vmware Vsphere Client
Vcenter