CVE-2016-5331: CRLF Injection
Published Aug 8, 2016
·Updated
CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Affected Software
2 affected components
VMware vCenter Server<=6.0
VMware ESXi=6.0
Remediation
Event History
Aug 8, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5331?
CVE-2016-5331 is considered a medium severity vulnerability.
2
How do I fix CVE-2016-5331?
To fix CVE-2016-5331, update VMware vCenter Server to version 6.0 update 2 or later, or update ESXi to a non-vulnerable version.
3
What systems are affected by CVE-2016-5331?
CVE-2016-5331 affects VMware vCenter Server versions prior to update 2 and VMware ESXi version 6.0.
4
What type of attack can be executed using CVE-2016-5331?
CVE-2016-5331 allows attackers to perform HTTP response splitting attacks by injecting arbitrary HTTP headers.
5
Is there a workaround for CVE-2016-5331 if I cannot update?
There are no documented workarounds for CVE-2016-5331, so updating to a secure version is recommended.