First published: Fri Dec 21 2012(Updated: )
VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 does not properly parse XML documents, which allows remote authenticated users to read arbitrary files via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vCenter Server Appliance | <=5.0 | |
VMware vCenter Server Appliance | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-6325 has a medium severity rating due to its potential to allow remote authenticated users to read arbitrary files.
To fix CVE-2012-6325, update VMware vCenter Server Appliance to version 5.0 Update 2 or later.
CVE-2012-6325 affects users of VMware vCenter Server Appliance versions up to and including 5.0 before Update 2.
CVE-2012-6325 is an XML parsing vulnerability that allows unauthorized file access.
Yes, CVE-2012-6325 can be exploited remotely by authenticated users.