PT-2016-2329 · Vmware · Vsphere Web Client+2

Published

2016-07-03

·

Updated

2017-09-01

·

CVE-2015-6931

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions VMware vCenter Server versions 5.0 before U3g VMware vCenter Server versions 5.1 before U3d VMware vCenter Server versions 5.5 before U2d
Description The issue is related to a cross-site scripting (XSS) vulnerability in the vSphere Web Client component. This vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted URL, potentially enabling them to execute malicious code on the client-side. The vulnerability exists due to insufficient protection of the web page structure.
Recommendations For versions 5.0 before U3g, update to U3g or later to resolve the issue. For versions 5.1 before U3d, update to U3d or later to resolve the issue. For versions 5.5 before U2d, update to U2d or later to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-01718
CVE-2015-6931

Affected Products

Vmware Vcenter
Vmware Vcenter Server
Vsphere Web Client