First published: Mon Aug 08 2016(Updated: )
CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vCenter | <=6.0 | |
VMware ESXi | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5331 is considered a medium severity vulnerability.
To fix CVE-2016-5331, update VMware vCenter Server to version 6.0 update 2 or later, or update ESXi to a non-vulnerable version.
CVE-2016-5331 affects VMware vCenter Server versions prior to update 2 and VMware ESXi version 6.0.
CVE-2016-5331 allows attackers to perform HTTP response splitting attacks by injecting arbitrary HTTP headers.
There are no documented workarounds for CVE-2016-5331, so updating to a secure version is recommended.