Vulnerability Name: | CVE-2016-7459 (CCN-119161) | ||||||||||||
Assigned: | 2016-11-22 | ||||||||||||
Published: | 2016-11-22 | ||||||||||||
Updated: | 2018-10-30 | ||||||||||||
Summary: | VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distributed Switch setup, or (3) Content Library XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | ||||||||||||
CVSS v3 Severity: | 7.7 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N) 6.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-611 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-7459 Source: BID Type: Third Party Advisory, VDB Entry 94486 Source: CCN Type: BID-94486 VMware vCenter Server CVE-2016-7459 XML External Entity Information Disclosure Vulnerability Source: SECTRACK Type: UNKNOWN 1037329 Source: CCN Type: VMware Security Advisory VMSA-2016-0022 VMware product updates address information disclosure vulnerabilities Source: CONFIRM Type: Patch, Vendor Advisory http://www.vmware.com/security/advisories/VMSA-2016-0022.html Source: XF Type: UNKNOWN vmware-vcenter-cve20167459-info-disc(119161) | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |