CVE-2012-6325: Infoleak
Published Dec 21, 2012
·Updated
VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 does not properly parse XML documents, which allows remote authenticated users to read arbitrary files via unspecified vectors.
Affected Software
2 affected components
VMware vCenter Server Appliance<=5.0
VMware vCenter Server Appliance=5.0
Event History
Dec 21, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-6325?
CVE-2012-6325 has a medium severity rating due to its potential to allow remote authenticated users to read arbitrary files.
2
How do I fix CVE-2012-6325?
To fix CVE-2012-6325, update VMware vCenter Server Appliance to version 5.0 Update 2 or later.
3
Who is affected by CVE-2012-6325?
CVE-2012-6325 affects users of VMware vCenter Server Appliance versions up to and including 5.0 before Update 2.
4
What type of vulnerability is CVE-2012-6325?
CVE-2012-6325 is an XML parsing vulnerability that allows unauthorized file access.
5
Can CVE-2012-6325 be exploited remotely?
Yes, CVE-2012-6325 can be exploited remotely by authenticated users.