5.8

CVE-2016-7458

VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Vsphere Client Version 5.5
VMware ≫ Vsphere Client Version 5.5 Update u1
VMware ≫ Vsphere Client Version 5.5 Update u2
VMware ≫ Vsphere Client Version 5.5 Update u3a
VMware ≫ Vsphere Client Version 5.5 Update u3b
VMware ≫ Vsphere Client Version 6.0
VMware ≫ Vsphere Client Version 6.0 Update 2
VMware ≫ Vsphere Client Version 6.0 Update 2m
VMware ≫ Vsphere Client Version 6.0 Update a
VMware ≫ Vsphere Client Version 6.0 Update b
VMware ≫ Vsphere Client Version 6.0 Update u1
VMware ≫ Vsphere Client Version 6.0 Update u1b
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.23% 0.649
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.8 3.9 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

http://www.securityfocus.com/bid/94483
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1037328
http://www.vmware.com/security/advisories/VMSA-2016-0022.html
Vendor Advisory