First published: Thu Dec 29 2016(Updated: )
VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distributed Switch setup, or (3) Content Library XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vCenter Server | =5.0 | |
VMware vCenter Server | =5.5 | |
VMware vCenter Server | =5.5-1 | |
VMware vCenter Server | =5.5-2 | |
VMware vCenter Server | =5.5-3a | |
VMware vCenter Server | =5.5-3b | |
VMware vCenter Server | =6.0 | |
VMware vCenter Server | =6.0-1 | |
VMware vCenter Server | =6.0-1b | |
VMware vCenter Server | =6.0-2 | |
VMware vCenter Server | =6.0-2m | |
VMware vCenter Server | =6.0-a | |
VMware vCenter Server | =6.0-b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.