PT-2016-2329 · Vmware · Vsphere Web Client+2
Published
2016-07-03
·
Updated
2017-09-01
·
CVE-2015-6931
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
VMware vCenter Server versions 5.0 before U3g
VMware vCenter Server versions 5.1 before U3d
VMware vCenter Server versions 5.5 before U2d
Description
The issue is related to a cross-site scripting (XSS) vulnerability in the vSphere Web Client component. This vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted URL, potentially enabling them to execute malicious code on the client-side. The vulnerability exists due to insufficient protection of the web page structure.
Recommendations
For versions 5.0 before U3g, update to U3g or later to resolve the issue.
For versions 5.1 before U3d, update to U3d or later to resolve the issue.
For versions 5.5 before U2d, update to U2d or later to resolve the issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vmware Vcenter
Vmware Vcenter Server
Vsphere Web Client