NEW VMSA-2016-0009 VMware vCenter Server updates address an important reflective cross-site scripting issue

VMware Security Response Center <[email protected]> Wed, 15 Jun 2016 05:28:59 +0000
Newsgroups gmane.comp.security.bugtraq,gmane.comp.security.full-disclosure
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----=0A=
Hash: SHA1=0A=
=0A=
- -----------------------------------------------------------------------=
=0A=
VMware Security Advisory=0A=
=0A=
Advisory ID: VMSA-2016-0009=0A=
Synopsis:    VMware vCenter Server updates address an important=0A=
             reflective cross-site scripting issue=0A=
Issue date:  2016-06-14=0A=
Updated on:  2016-06-14 (Initial Advisory)=0A=
CVE number:  CVE-2015-6931=0A=
- ------------------------------------------------------------------------=
=0A=
=0A=
1. Summary=0A=
=0A=
   VMware vCenter Server updates address an important reflective=0A=
   cross-site scripting issue.=0A=
=0A=
2. Relevant Releases=0A=
=0A=
   vCenter Server 5.5 prior to 5.5 update 2d=0A=
   vCenter Server 5.1 prior to 5.1 update 3d=0A=
   vCenter Server 5.0 prior to 5.0 update 3g=0A=
=0A=
=0A=
3. Problem Description=0A=
=0A=
   a. Important vCenter Server reflected cross-site scripting issue=0A=
=0A=
   The vSphere Web Client contains a reflected cross-site scripting=0A=
   vulnerability due to a lack of input sanitization. An attacker can=0A=
   exploit this issue by tricking a victim into clicking a malicious=0A=
   link.=0A=
=0A=
   VMware would like to thank Matt Schmidt for reporting this issue to=0A=
   us.=0A=
=0A=
   The Common Vulnerabilities and Exposures project (cve.mitre.org) has=0A=
   assigned the identifier CVE-2015-6931 to this issue.=0A=
=0A=
   Column 4 of the following table lists the action required to=0A=
   remediate the vulnerability in each release, if a solution is=0A=
   available.=0A=
=0A=
   VMware             Product    Running   Replace with/=0A=
   Product            Version    on        Apply Patch=0A=
   =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D     =3D=3D=3D=3D=3D=3D=3D    =
=3D=3D=3D=3D=3D=3D=3D   =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=0A=
   vCenter Server     6.0        Any       not affected=0A=
   vCenter Server     5.5        Any       5.5 U2d *=0A=
   vCenter Server     5.1        Any       5.1 U3d *=0A=
   vCenter Server     5.0        Any       5.0 U3g *=0A=
=0A=
   * The client side component of the vSphere Web Client does not need=0A=
     to be updated to remediate CVE-2015-6931. Updating the vCenter=0A=
     Server is sufficient to remediate this issue.=0A=
=0A=
=0A=
4. Solution=0A=
=0A=
   Please review the patch/release notes for your product and=0A=
   version and verify the checksum of your downloaded file.=0A=
=0A=
   vCenter Server=0A=
   --------------=0A=
   Downloads and Documentation:=0A=
   https://www.vmware.com/go/download-vsphere=0A=
=0A=
=0A=
5. References=0A=
=0A=
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2015-6931=0A=
=0A=
- ------------------------------------------------------------------------=
=0A=
=0A=
6. Change log=0A=
=0A=
   2016-06-14 VMSA-2016-0009=0A=
   Initial security advisory in conjunction with the release of VMware=0A=
   vCenter Server 5.0 U3g on 2016-06-14.=0A=
=0A=
- ------------------------------------------------------------------------=
=0A=
=0A=
7. Contact=0A=
=0A=
   E-mail list for product security notifications and announcements:=0A=
   http://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce=0A=
=0A=
   This Security Advisory is posted to the following lists:=0A=
=0A=
   security-announce at lists.vmware.com=0A=
   bugtraq at securityfocus.com=0A=
   fulldisclosure at seclists.org=0A=
=0A=
   E-mail: security at vmware.com=0A=
   PGP key at: https://kb.vmware.com/kb/1055=0A=
=0A=
   VMware Security Advisories=0A=
   http://www.vmware.com/security/advisories=0A=
=0A=
   Consolidated list of VMware Security Advisories=0A=
   http://kb.vmware.com/kb/2078735=0A=
=0A=
   VMware Security Response Policy=0A=
   https://www.vmware.com/support/policies/security_response.html=0A=
=0A=
   VMware Lifecycle Support Phases=0A=
   https://www.vmware.com/support/policies/lifecycle.html=0A=
=0A=
   Twitter=0A=
   https://twitter.com/VMwareSRC=0A=
=0A=
   Copyright 2016 VMware Inc.  All rights reserved.=0A=
=0A=
-----BEGIN PGP SIGNATURE-----=0A=
Version: PGP Desktop 9.8.3 (Build 4028)=0A=
Charset: utf-8=0A=
=0A=
wj8DBQFXYOczDEcm8Vbi9kMRApfPAJ0Urm1NrLwTbkY0vsGeXQtS0kWDZQCgmYPj=0A=
dGcJx5HCyLJCiIz/FCMpGIU=3D=0A=
=3DFYiK=0A=
-----END PGP SIGNATURE-----=0A=