SB2015091901 - Multiple vulnerabilities in VMware, vCenter Server



SB2015091901 - Multiple vulnerabilities in VMware, vCenter Server

Published: September 19, 2015 Updated: August 9, 2020

Security Bulletin ID SB2015091901
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) XML External Entity injection (CVE-ID: CVE-2016-7459)

The vulnerability allows a remote authenticated user to gain access to sensitive information.

VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distributed Switch setup, or (3) Content Library XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.


2) Cryptographic issues (CVE-ID: CVE-2015-6932)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.


Remediation

Install update from vendor's website.