CVE-2016-5334: Medium severity vmware workspace one access and identity manager vulnerability
VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF files via unspecified vectors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5334?
CVE-2016-5334 has been classified as a moderate severity vulnerability due to potential exposure of sensitive files.
How do I fix CVE-2016-5334?
To fix CVE-2016-5334, upgrade VMware Identity Manager to version 2.7.1 or vRealize Automation to version 7.2.0 or later.
What are the potential impacts of CVE-2016-5334?
The potential impacts of CVE-2016-5334 include unauthorized access to internal configuration files, which could lead to further attacks.
Which versions are affected by CVE-2016-5334?
CVE-2016-5334 affects VMware Identity Manager versions before 2.7.1 and vRealize Automation versions before 7.2.0.
Can CVE-2016-5334 be exploited remotely?
Yes, CVE-2016-5334 can be exploited remotely by attackers to read sensitive files if the proper security controls are not in place.