First published: Mon Dec 08 2014(Updated: )
Cross-site scripting (XSS) vulnerability in VMware vCenter Server Appliance (vCSA) 5.1 before Update 3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vCenter Server Appliance | =5.1 | |
VMware vCenter Server Appliance | =5.1-update_1 | |
VMware vCenter Server Appliance | =5.1-update_2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3797 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2014-3797, update VMware vCenter Server Appliance to version 5.1 Update 3 or later.
CVE-2014-3797 affects VMware vCenter Server Appliance version 5.1 and its updates 1 and 2.
CVE-2014-3797 is a cross-site scripting vulnerability that allows injection of arbitrary web script or HTML.
Yes, CVE-2014-3797 can be exploited remotely by attackers through unspecified vectors.