NEW VMSA-2016-0004 VMware product updates address a critical security issue in the VMware Client Integration Plugin

VMware Security Response Center <[email protected]> Thu, 14 Apr 2016 19:39:20 +0000
Newsgroups gmane.comp.security.bugtraq,gmane.comp.security.full-disclosure
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----=0A=
Hash: SHA1=0A=
=0A=
- ------------------------------------------------------------------------=
=0A=
                   VMware Security Advisory=0A=
=0A=
Advisory ID: VMSA-2016-0004=0A=
Synopsis:    VMware product updates address a critical security issue in=0A=
             the VMware Client Integration Plugin=0A=
Issue date:  2016-04-14=0A=
Updated on:  2016-04-14 (Initial Advisory)=0A=
CVE number:  CVE-2016-2076=0A=
 =0A=
1. Summary=0A=
=0A=
   VMware vCenter Server, vCloud Director (vCD), vRealize Automation=0A=
   (vRA) Identity Appliance, and the Client Integration Plugin (CIP)=0A=
   updates address a critical security issue.=0A=
=0A=
2. Relevant Releases=0A=
=0A=
   vCenter Server 6.0=0A=
   vCenter Server 5.5 U3a, U3b, U3c=0A=
 =0A=
   vCloud Director 5.5.5=0A=
  =0A=
   vRealize Automation Identity Appliance 6.2.4=0A=
=0A=
3. Problem Description=0A=
=0A=
   a. Critical VMware Client Integration Plugin incorrect session=0A=
      handling=0A=
=0A=
   The VMware Client Integration Plugin does not handle session content=0A=
   in a safe way. This may allow for a Man in the Middle attack or Web=0A=
   session hijacking in case the user of the vSphere Web Client visits=0A=
   a malicious Web site.=0A=
=0A=
   The vulnerability is present in versions of CIP that shipped with:=0A=
   - vCenter Server 6.0 (any 6.0 version up to 6.0 U2)=0A=
   - vCenter Server 5.5 U3a, U3b, U3c=0A=
   - vCloud Director 5.5.5=0A=
   - vRealize Automation Identity Appliance 6.2.4=0A=
=0A=
   In order to remediate the issue, both the server side (i.e. vCenter=0A=
   Server, vCloud Director, and vRealize Automation Identity Appliance)=0A=
   and the client side (i.e. CIP of the vSphere Web Client) will need=0A=
   to be updated.=0A=
=0A=
   The steps to remediate the issue are as follows:=0A=
   A) Install an updated version of:=0A=
      - vCenter Server,=0A=
      - vCloud Director,=0A=
      - vRealize Automation Identity Appliance,=0A=
   B) Subsequently update the Client Integration Plugin on the system=0A=
      from which the vSphere Web Client is used.=0A=
      Updating the plugin on vSphere and vRA Identity Appliance is=0A=
      explained in VMware Knowledge Base article 2145066.=0A=
      Updating the plugin on vCloud Director is initiated by a prompt=0A=
      when connecting the vSphere Web Client to the updated version of=0A=
      vCloud Director.=0A=
=0A=
   The Common Vulnerabilities and Exposures project (cve.mitre.org) has=0A=
   assigned the identifier CVE-2016-2076 to this issue.=0A=
=0A=
   Column 4 of the following table lists the action required to=0A=
   remediate the vulnerability in each release, if a solution is=0A=
   available.=0A=
=0A=
   VMware                  Product        Running   Replace with/=0A=
   Product                 Version        on        Apply Patch=0A=
   =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D  =3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D  =3D=3D=3D=3D=3D=3D=3D   =3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=0A=
  =0A=
   vCenter Server          6.0            any       6.0 U2 *=0A=
   vCenter Server          5.5 U3a - U3c  any       5.5 U3d *=0A=
   vCenter Server          5.1            any       not affected=0A=
   vCenter Server          5.0            any       not affected =0A=
=0A=
   vCloud Director         8.0.x          Windows   not affected **=0A=
   vCloud Director         5.6.x          Windows   not affected=0A=
   vCloud Director         5.5.5          Windows   5.5.6 *=0A=
=0A=
   vRA Identity Appliance  7.x            Linux     not affected=0A=
   vRA Identity Appliance  6.2.4          Linux     6.2.4.1 *=0A=
=0A=
   Client Integration      see text       Windows,  see item B above=0A=
   Plugin                  above          Mac OS=0A=
  =0A=
   * After installing the updated version, the Client Integration Plugin=0A=
     will need to be updated on all systems from which the vSphere Web=0A=
     Client is used to connect to vCenter Server, vCloud Director and=0A=
     vRealize Automation Identity Manager.=0A=
=0A=
  ** vCloud Director 8.0.0 did not ship with a vulnerable CIP version,=0A=
      and vCloud Director 8.0.1 shipped with the updated version of the=0A=
      CIP.=0A=
=0A=
4. Solution=0A=
=0A=
   Please review the patch/release notes for your product and=0A=
   version and verify the checksum of your downloaded file.=0A=
=0A=
   vCenter Server=0A=
   --------------=0A=
   Downloads and Documentation:=0A=
   https://www.vmware.com/go/download-vsphere=0A=
 =0A=
http://pubs.vmware.com/Release_Notes/en/vsphere/55/vsphere-vcenter-server-5=
=0A=
5u3d-release-notes.html=0A=
=0A=
   vCloud Director=0A=
   ---------------=0A=
   Downloads and Documentation:=0A=
   https://www.vmware.com/go/download/vcloud-director=0A=
 =0A=
http://pubs.vmware.com/Release_Notes/en/vcd/556/rel_notes_vcloud_director_5=
=0A=
56.html=0A=
=0A=
   VMware vRealize Automation 6.2.4.1=0A=
   ----------------------------------=0A=
   Downloads and Documentation:=0A=
 =0A=
https://my.vmware.com/web/vmware/info/slug/infrastructure_operations_manage=
=0A=
ment/vmware_vrealize_automation/6_2=0A=
   (select "Go to Downloads" and scroll down to "Security Update")=0A=
 =0A=
http://pubs.vmware.com/Release_Notes/en/vra/vrealize-automation-624-release=
=0A=
- -notes.html=0A=
=0A=
=0A=
5. References=0A=
=0A=
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2016-2076=0A=
=0A=
   VMware Knowledge Base article 2145066=0A=
   kb.vmware.com/kb/2145066=0A=
=0A=
- ------------------------------------------------------------------------=
=0A=
=0A=
6. Change log=0A=
=0A=
   2016-04-14 VMSA-2016-0004=0A=
   Initial security advisory in conjunction with the release of VMware=0A=
   vSphere 5.5 U3d and vCloud Director 5.5.6 on 2016-04-14.=0A=
=0A=
- ------------------------------------------------------------------------=
=0A=
=0A=
7. Contact=0A=
=0A=
   E-mail list for product security notifications and announcements:=0A=
   http://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce=0A=
=0A=
   This Security Advisory is posted to the following lists:=0A=
=0A=
    security-announce at lists.vmware.com=0A=
    bugtraq at securityfocus.com=0A=
    fulldisclosure at seclists.org=0A=
=0A=
   E-mail: security at vmware.com=0A=
   PGP key at: https://kb.vmware.com/kb/1055=0A=
=0A=
   VMware Security Advisories=0A=
   http://www.vmware.com/security/advisories=0A=
=0A=
   Consolidated list of VMware Security Advisories=0A=
   http://kb.vmware.com/kb/2078735=0A=
=0A=
   VMware Security Response Policy=0A=
   https://www.vmware.com/support/policies/security_response.html=0A=
=0A=
   VMware Lifecycle Support Phases=0A=
   https://www.vmware.com/support/policies/lifecycle.html=0A=
=0A=
   Twitter=0A=
   https://twitter.com/VMwareSRC=0A=
=0A=
   Copyright 2016 VMware Inc.  All rights reserved.=0A=
=0A=
-----BEGIN PGP SIGNATURE-----=0A=
Version: PGP Desktop 9.8.3 (Build 4028)=0A=
Charset: utf-8=0A=
=0A=
wj8DBQFXD+2rDEcm8Vbi9kMRAkavAJ9Jh0+7d46fu6t24ZTbfi+gZqNhNACfbiip=0A=
CTomNkThpHn4T6WPTz8LAuw=3D=0A=
=3DDZIG=0A=
-----END PGP SIGNATURE-----=