CVE-2017-4928: SSRF
The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRLF injection issues due to improper neutralization of URLs. An attacker may exploit these issues by sending a POST request with modified headers towards internal services leading to information disclosure.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-4928?
CVE-2017-4928 is a vulnerability in the flash-based vSphere Web Client that allows SSRF and CRLF injection attacks.
What is the severity of CVE-2017-4928?
The severity of CVE-2017-4928 is high, with a severity value of 7.5.
What is the affected software for CVE-2017-4928?
The affected software for CVE-2017-4928 is VMware vCenter Server versions 5.5 and 6.0.
How can an attacker exploit CVE-2017-4928?
An attacker can exploit CVE-2017-4928 by sending a POST request with modified headers towards the vSphere Web Client.
Where can I find more information about CVE-2017-4928?
More information about CVE-2017-4928 can be found on the following websites: SecurityFocus, SecurityTracker, and VMware's security advisories.