First published: Wed Mar 16 2016(Updated: )
Cross-site scripting (XSS) vulnerability in VMware vRealize Business Advanced and Enterprise 8.x before 8.2.5 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vRealize Business Advanced and Enterprise | =8.0 | |
VMware vRealize Business Advanced and Enterprise | =8.0.1 | |
VMware vRealize Business Advanced and Enterprise | =8.0.2 | |
VMware vRealize Business Advanced and Enterprise | =8.1 | |
VMware vRealize Business Advanced and Enterprise | =8.2 | |
VMware vRealize Business Advanced and Enterprise | =8.2.1 | |
VMware vRealize Business Advanced and Enterprise | =8.2.2 | |
VMware vRealize Business Advanced and Enterprise | =8.2.3 | |
VMware vRealize Business Advanced and Enterprise | =8.2.4 | |
Linux Kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2075 is considered a medium severity vulnerability due to the potential for unauthorized web script execution.
To remediate CVE-2016-2075, it is recommended to update VMware vRealize Business Advanced and Enterprise to version 8.2.5 or later.
CVE-2016-2075 affects remote authenticated users of VMware vRealize Business Advanced and Enterprise versions prior to 8.2.5.
CVE-2016-2075 is a cross-site scripting (XSS) vulnerability that allows for the injection of arbitrary web scripts or HTML.
Exploiting CVE-2016-2075 could allow an attacker to execute malicious scripts in the context of the user's browser, potentially leading to data theft or session hijacking.