XML External Entity injection in vCenter Server - CVE-2016-7459

 

XML External Entity injection in vCenter Server - CVE-2016-7459

Published: December 29, 2016 / Updated: August 9, 2020


Vulnerability identifier: #VU39958
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2016-7459
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: VMware, Inc
Affected software:
vCenter Server

Detailed vulnerability description

The vulnerability allows a remote authenticated user to gain access to sensitive information.

VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distributed Switch setup, or (3) Content Library XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.


How to mitigate CVE-2016-7459

Install update from vendor's website.

Sources