First published: Wed Dec 20 2017(Updated: )
The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESXi550-201709102-SG) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker can exploit this vulnerability by injecting Javascript, which might get executed when other users access the Host Client.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware ESXi and Horizon DaaS | =5.5 | |
VMware ESXi and Horizon DaaS | =5.5-1 | |
VMware ESXi and Horizon DaaS | =5.5-2 | |
VMware ESXi and Horizon DaaS | =5.5-3a | |
VMware ESXi and Horizon DaaS | =5.5-3b | |
VMware ESXi and Horizon DaaS | =5.5-550-20170901001s | |
VMware ESXi and Horizon DaaS | =6.0 | |
VMware ESXi and Horizon DaaS | =6.0-1 | |
VMware ESXi and Horizon DaaS | =6.0-1a | |
VMware ESXi and Horizon DaaS | =6.0-1b | |
VMware ESXi and Horizon DaaS | =6.0-2 | |
VMware ESXi and Horizon DaaS | =6.0-3 | |
VMware ESXi and Horizon DaaS | =6.0-3a | |
VMware ESXi and Horizon DaaS | =6.0-600-201504401 | |
VMware ESXi and Horizon DaaS | =6.0-600-201505401 | |
VMware ESXi and Horizon DaaS | =6.0-600-201507101 | |
VMware ESXi and Horizon DaaS | =6.0-600-201507102 | |
VMware ESXi and Horizon DaaS | =6.0-600-201507401 | |
VMware ESXi and Horizon DaaS | =6.0-600-201507402 | |
VMware ESXi and Horizon DaaS | =6.0-600-201507403 | |
VMware ESXi and Horizon DaaS | =6.0-600-201507404 | |
VMware ESXi and Horizon DaaS | =6.0-600-201507405 | |
VMware ESXi and Horizon DaaS | =6.0-600-201507406 | |
VMware ESXi and Horizon DaaS | =6.0-600-201507407 | |
VMware ESXi and Horizon DaaS | =6.0-600-201509101 | |
VMware ESXi and Horizon DaaS | =6.0-600-201509102 | |
VMware ESXi and Horizon DaaS | =6.0-600-201509201 | |
VMware ESXi and Horizon DaaS | =6.0-600-201509202 | |
VMware ESXi and Horizon DaaS | =6.0-600-201509203 | |
VMware ESXi and Horizon DaaS | =6.0-600-201509204 | |
VMware ESXi and Horizon DaaS | =6.0-600-201509205 | |
VMware ESXi and Horizon DaaS | =6.0-600-201509206 | |
VMware ESXi and Horizon DaaS | =6.0-600-201509207 | |
VMware ESXi and Horizon DaaS | =6.0-600-201509208 | |
VMware ESXi and Horizon DaaS | =6.0-600-201509209 | |
VMware ESXi and Horizon DaaS | =6.0-600-201509210 | |
VMware ESXi and Horizon DaaS | =6.0-600-201510401 | |
VMware ESXi and Horizon DaaS | =6.0-600-201511401 | |
VMware ESXi and Horizon DaaS | =6.0-600-201601101 | |
VMware ESXi and Horizon DaaS | =6.0-600-201601102 | |
VMware ESXi and Horizon DaaS | =6.0-600-201601401 | |
VMware ESXi and Horizon DaaS | =6.0-600-201601402 | |
VMware ESXi and Horizon DaaS | =6.0-600-201601403 | |
VMware ESXi and Horizon DaaS | =6.0-600-201601404 | |
VMware ESXi and Horizon DaaS | =6.0-600-201601405 | |
VMware ESXi and Horizon DaaS | =6.0-600-201602401 | |
VMware ESXi and Horizon DaaS | =6.0-600-201603101 | |
VMware ESXi and Horizon DaaS | =6.0-600-201603102 | |
VMware ESXi and Horizon DaaS | =6.0-600-201603201 | |
VMware ESXi and Horizon DaaS | =6.0-600-201603202 | |
VMware ESXi and Horizon DaaS | =6.0-600-201603203 | |
VMware ESXi and Horizon DaaS | =6.0-600-201603204 | |
VMware ESXi and Horizon DaaS | =6.0-600-201603205 | |
VMware ESXi and Horizon DaaS | =6.0-600-201603206 | |
VMware ESXi and Horizon DaaS | =6.0-600-201603207 | |
VMware ESXi and Horizon DaaS | =6.0-600-201603208 | |
VMware ESXi and Horizon DaaS | =6.0-600-201605401 | |
VMware ESXi and Horizon DaaS | =6.0-600-201608101 | |
VMware ESXi and Horizon DaaS | =6.0-600-201608401 | |
VMware ESXi and Horizon DaaS | =6.0-600-201608402 | |
VMware ESXi and Horizon DaaS | =6.0-600-201608403 | |
VMware ESXi and Horizon DaaS | =6.0-600-201608404 | |
VMware ESXi and Horizon DaaS | =6.0-600-201608405 | |
VMware ESXi and Horizon DaaS | =6.0-600-201610410 | |
VMware ESXi and Horizon DaaS | =6.0-600-201611401 | |
VMware ESXi and Horizon DaaS | =6.0-600-201611402 | |
VMware ESXi and Horizon DaaS | =6.0-600-201611403 | |
VMware ESXi and Horizon DaaS | =6.0-600-201702101 | |
VMware ESXi and Horizon DaaS | =6.0-600-201702102 | |
VMware ESXi and Horizon DaaS | =6.0-600-201702201 | |
VMware ESXi and Horizon DaaS | =6.0-600-201702202 | |
VMware ESXi and Horizon DaaS | =6.0-600-201702203 | |
VMware ESXi and Horizon DaaS | =6.0-600-201702204 | |
VMware ESXi and Horizon DaaS | =6.0-600-201702205 | |
VMware ESXi and Horizon DaaS | =6.0-600-201702206 | |
VMware ESXi and Horizon DaaS | =6.0-600-201702207 | |
VMware ESXi and Horizon DaaS | =6.0-600-201702208 | |
VMware ESXi and Horizon DaaS | =6.0-600-201702209 | |
VMware ESXi and Horizon DaaS | =6.0-600-201702210 | |
VMware ESXi and Horizon DaaS | =6.0-600-201702211 | |
VMware ESXi and Horizon DaaS | =6.0-600-201702212 | |
VMware ESXi and Horizon DaaS | =6.0-600-201703401 | |
VMware ESXi and Horizon DaaS | =6.0-600-201706101 | |
VMware ESXi and Horizon DaaS | =6.0-600-201706102 | |
VMware ESXi and Horizon DaaS | =6.0-600-201706103 | |
VMware ESXi and Horizon DaaS | =6.0-600-201706401 | |
VMware ESXi and Horizon DaaS | =6.0-600-201706402 | |
VMware ESXi and Horizon DaaS | =6.0-600-201706403 | |
VMware ESXi and Horizon DaaS | =6.0-600-201710301 | |
VMware ESXi and Horizon DaaS | =6.5 | |
VMware ESXi and Horizon DaaS | =6.5-650-201701001 | |
VMware ESXi and Horizon DaaS | =6.5-650-201703001 | |
VMware ESXi and Horizon DaaS | =6.5-650-201703002 | |
VMware ESXi and Horizon DaaS | =6.5-650-201704001 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707101 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707102 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707103 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707201 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707202 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707203 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707204 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707205 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707206 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707207 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707208 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707209 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707210 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707211 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707212 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707213 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707214 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707215 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707216 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707217 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707218 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707219 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707220 | |
VMware ESXi and Horizon DaaS | =6.5-650-201707221 | |
VMware ESXi and Horizon DaaS | =6.5-650-201710001 | |
VMware ESXi and Horizon DaaS | =6.5-650-201712001 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Symptoms of exploitation may include unexpected behavior in the ESXi Host Client interface or unauthorized actions executed within the context of a user session.