SB2016100702 - Directory traversal in VMware Horizon View



SB2016100702 - Directory traversal in VMware Horizon View

Published: October 7, 2016

Security Bulletin ID SB2016100702
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Directory traversal (CVE-ID: CVE-2016-7087)

The vulnerability allows a remote unauthenticated user to view potentially sensitive information on the target system.
The weakness exists due to directory traversal flaw and lets attackers to obtain certain information from the Horizon View Connection Server.
Successful exploitation of the vulnerability results in disclosure of important data.

Remediation

Install update from vendor's website.