XML External Entity injection in vCenter Server - CVE-2016-7459

 

XML External Entity injection in vCenter Server - CVE-2016-7459

Published: December 29, 2016 / Updated: August 9, 2020


Vulnerability identifier: #VU39958
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2016-7459
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to gain access to sensitive information.

VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distributed Switch setup, or (3) Content Library XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.


Affected software

vCenter Server

How to mitigate CVE-2016-7459

Install update from vendor's website.


External References

Related Security Bulletins