First published: Thu Dec 29 2016(Updated: )
VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vSphere Client | =5.5 | |
VMware vSphere Client | =5.5-u1 | |
VMware vSphere Client | =5.5-u2 | |
VMware vSphere Client | =5.5-u3a | |
VMware vSphere Client | =5.5-u3b | |
VMware vSphere Client | =6.0 | |
VMware vSphere Client | =6.0-2 | |
VMware vSphere Client | =6.0-2m | |
VMware vSphere Client | =6.0-a | |
VMware vSphere Client | =6.0-b | |
VMware vSphere Client | =6.0-u1 | |
VMware vSphere Client | =6.0-u1b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7458 is considered a critical vulnerability due to its potential for remote file reading and data exposure.
To fix CVE-2016-7458, upgrade to VMware vSphere Client versions 5.5 U3e or 6.0 U2a or later.
CVE-2016-7458 affects VMware vSphere Client versions 5.5 before U3e and 6.0 before U2a.
CVE-2016-7458 can be exploited through XML External Entity (XXE) injection attacks.
No effective workaround exists for CVE-2016-7458 other than applying the recommended updates.