NEW VMSA-2016-0004 VMware product updates address a critical security issue in the VMware Client Integration Plugin
VMware Security Response Center <[email protected]> Thu, 14 Apr 2016 19:39:20 +0000
| Newsgroups | gmane.comp.security.bugtraq,gmane.comp.security.full-disclosure |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE-----=0A=
Hash: SHA1=0A=
=0A=
- ------------------------------------------------------------------------=
=0A=
VMware Security Advisory=0A=
=0A=
Advisory ID: VMSA-2016-0004=0A=
Synopsis: VMware product updates address a critical security issue in=0A=
the VMware Client Integration Plugin=0A=
Issue date: 2016-04-14=0A=
Updated on: 2016-04-14 (Initial Advisory)=0A=
CVE number: CVE-2016-2076=0A=
=0A=
1. Summary=0A=
=0A=
VMware vCenter Server, vCloud Director (vCD), vRealize Automation=0A=
(vRA) Identity Appliance, and the Client Integration Plugin (CIP)=0A=
updates address a critical security issue.=0A=
=0A=
2. Relevant Releases=0A=
=0A=
vCenter Server 6.0=0A=
vCenter Server 5.5 U3a, U3b, U3c=0A=
=0A=
vCloud Director 5.5.5=0A=
=0A=
vRealize Automation Identity Appliance 6.2.4=0A=
=0A=
3. Problem Description=0A=
=0A=
a. Critical VMware Client Integration Plugin incorrect session=0A=
handling=0A=
=0A=
The VMware Client Integration Plugin does not handle session content=0A=
in a safe way. This may allow for a Man in the Middle attack or Web=0A=
session hijacking in case the user of the vSphere Web Client visits=0A=
a malicious Web site.=0A=
=0A=
The vulnerability is present in versions of CIP that shipped with:=0A=
- vCenter Server 6.0 (any 6.0 version up to 6.0 U2)=0A=
- vCenter Server 5.5 U3a, U3b, U3c=0A=
- vCloud Director 5.5.5=0A=
- vRealize Automation Identity Appliance 6.2.4=0A=
=0A=
In order to remediate the issue, both the server side (i.e. vCenter=0A=
Server, vCloud Director, and vRealize Automation Identity Appliance)=0A=
and the client side (i.e. CIP of the vSphere Web Client) will need=0A=
to be updated.=0A=
=0A=
The steps to remediate the issue are as follows:=0A=
A) Install an updated version of:=0A=
- vCenter Server,=0A=
- vCloud Director,=0A=
- vRealize Automation Identity Appliance,=0A=
B) Subsequently update the Client Integration Plugin on the system=0A=
from which the vSphere Web Client is used.=0A=
Updating the plugin on vSphere and vRA Identity Appliance is=0A=
explained in VMware Knowledge Base article 2145066.=0A=
Updating the plugin on vCloud Director is initiated by a prompt=0A=
when connecting the vSphere Web Client to the updated version of=0A=
vCloud Director.=0A=
=0A=
The Common Vulnerabilities and Exposures project (cve.mitre.org) has=0A=
assigned the identifier CVE-2016-2076 to this issue.=0A=
=0A=
Column 4 of the following table lists the action required to=0A=
remediate the vulnerability in each release, if a solution is=0A=
available.=0A=
=0A=
VMware Product Running Replace with/=0A=
Product Version on Apply Patch=0A=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D =3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D =3D=3D=3D=3D=3D=3D=3D =3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=0A=
=0A=
vCenter Server 6.0 any 6.0 U2 *=0A=
vCenter Server 5.5 U3a - U3c any 5.5 U3d *=0A=
vCenter Server 5.1 any not affected=0A=
vCenter Server 5.0 any not affected =0A=
=0A=
vCloud Director 8.0.x Windows not affected **=0A=
vCloud Director 5.6.x Windows not affected=0A=
vCloud Director 5.5.5 Windows 5.5.6 *=0A=
=0A=
vRA Identity Appliance 7.x Linux not affected=0A=
vRA Identity Appliance 6.2.4 Linux 6.2.4.1 *=0A=
=0A=
Client Integration see text Windows, see item B above=0A=
Plugin above Mac OS=0A=
=0A=
* After installing the updated version, the Client Integration Plugin=0A=
will need to be updated on all systems from which the vSphere Web=0A=
Client is used to connect to vCenter Server, vCloud Director and=0A=
vRealize Automation Identity Manager.=0A=
=0A=
** vCloud Director 8.0.0 did not ship with a vulnerable CIP version,=0A=
and vCloud Director 8.0.1 shipped with the updated version of the=0A=
CIP.=0A=
=0A=
4. Solution=0A=
=0A=
Please review the patch/release notes for your product and=0A=
version and verify the checksum of your downloaded file.=0A=
=0A=
vCenter Server=0A=
--------------=0A=
Downloads and Documentation:=0A=
https://www.vmware.com/go/download-vsphere=0A=
=0A=
http://pubs.vmware.com/Release_Notes/en/vsphere/55/vsphere-vcenter-server-5=
=0A=
5u3d-release-notes.html=0A=
=0A=
vCloud Director=0A=
---------------=0A=
Downloads and Documentation:=0A=
https://www.vmware.com/go/download/vcloud-director=0A=
=0A=
http://pubs.vmware.com/Release_Notes/en/vcd/556/rel_notes_vcloud_director_5=
=0A=
56.html=0A=
=0A=
VMware vRealize Automation 6.2.4.1=0A=
----------------------------------=0A=
Downloads and Documentation:=0A=
=0A=
https://my.vmware.com/web/vmware/info/slug/infrastructure_operations_manage=
=0A=
ment/vmware_vrealize_automation/6_2=0A=
(select "Go to Downloads" and scroll down to "Security Update")=0A=
=0A=
http://pubs.vmware.com/Release_Notes/en/vra/vrealize-automation-624-release=
=0A=
- -notes.html=0A=
=0A=
=0A=
5. References=0A=
=0A=
http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2016-2076=0A=
=0A=
VMware Knowledge Base article 2145066=0A=
kb.vmware.com/kb/2145066=0A=
=0A=
- ------------------------------------------------------------------------=
=0A=
=0A=
6. Change log=0A=
=0A=
2016-04-14 VMSA-2016-0004=0A=
Initial security advisory in conjunction with the release of VMware=0A=
vSphere 5.5 U3d and vCloud Director 5.5.6 on 2016-04-14.=0A=
=0A=
- ------------------------------------------------------------------------=
=0A=
=0A=
7. Contact=0A=
=0A=
E-mail list for product security notifications and announcements:=0A=
http://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce=0A=
=0A=
This Security Advisory is posted to the following lists:=0A=
=0A=
security-announce at lists.vmware.com=0A=
bugtraq at securityfocus.com=0A=
fulldisclosure at seclists.org=0A=
=0A=
E-mail: security at vmware.com=0A=
PGP key at: https://kb.vmware.com/kb/1055=0A=
=0A=
VMware Security Advisories=0A=
http://www.vmware.com/security/advisories=0A=
=0A=
Consolidated list of VMware Security Advisories=0A=
http://kb.vmware.com/kb/2078735=0A=
=0A=
VMware Security Response Policy=0A=
https://www.vmware.com/support/policies/security_response.html=0A=
=0A=
VMware Lifecycle Support Phases=0A=
https://www.vmware.com/support/policies/lifecycle.html=0A=
=0A=
Twitter=0A=
https://twitter.com/VMwareSRC=0A=
=0A=
Copyright 2016 VMware Inc. All rights reserved.=0A=
=0A=
-----BEGIN PGP SIGNATURE-----=0A=
Version: PGP Desktop 9.8.3 (Build 4028)=0A=
Charset: utf-8=0A=
=0A=
wj8DBQFXD+2rDEcm8Vbi9kMRAkavAJ9Jh0+7d46fu6t24ZTbfi+gZqNhNACfbiip=0A=
CTomNkThpHn4T6WPTz8LAuw=3D=0A=
=3DDZIG=0A=
-----END PGP SIGNATURE-----=