CVE-2015-2344: XSS
Published Mar 16, 2016
·Updated
Cross-site scripting (XSS) vulnerability in VMware vRealize Automation 6.x before 6.2.4 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
11 affected components
Linux Linux kernel
VMware vRealize Automation=6.0
VMware vRealize Automation=6.0.1
VMware vRealize Automation=6.0.1.1
VMware vRealize Automation=6.0.1.2
VMware vRealize Automation=6.1
VMware vRealize Automation=6.1.1
VMware vRealize Automation=6.2
VMware vRealize Automation=6.2.1
VMware vRealize Automation=6.2.2
VMware vRealize Automation=6.2.3
Event History
Mar 16, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2344?
CVE-2015-2344 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-2344?
To fix CVE-2015-2344, upgrade VMware vRealize Automation to version 6.2.4 or later.
3
Who is affected by CVE-2015-2344?
CVE-2015-2344 affects VMware vRealize Automation versions 6.0 to 6.2.3 on Linux.
4
What type of vulnerability is CVE-2015-2344?
CVE-2015-2344 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2015-2344 be exploited remotely?
Yes, CVE-2015-2344 can be exploited by remote authenticated users.