NEW VMSA-2016-0009 VMware vCenter Server updates address an important reflective cross-site scripting issue
VMware Security Response Center <[email protected]> Wed, 15 Jun 2016 05:28:59 +0000
| Newsgroups | gmane.comp.security.bugtraq,gmane.comp.security.full-disclosure |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE-----=0A=
Hash: SHA1=0A=
=0A=
- -----------------------------------------------------------------------=
=0A=
VMware Security Advisory=0A=
=0A=
Advisory ID: VMSA-2016-0009=0A=
Synopsis: VMware vCenter Server updates address an important=0A=
reflective cross-site scripting issue=0A=
Issue date: 2016-06-14=0A=
Updated on: 2016-06-14 (Initial Advisory)=0A=
CVE number: CVE-2015-6931=0A=
- ------------------------------------------------------------------------=
=0A=
=0A=
1. Summary=0A=
=0A=
VMware vCenter Server updates address an important reflective=0A=
cross-site scripting issue.=0A=
=0A=
2. Relevant Releases=0A=
=0A=
vCenter Server 5.5 prior to 5.5 update 2d=0A=
vCenter Server 5.1 prior to 5.1 update 3d=0A=
vCenter Server 5.0 prior to 5.0 update 3g=0A=
=0A=
=0A=
3. Problem Description=0A=
=0A=
a. Important vCenter Server reflected cross-site scripting issue=0A=
=0A=
The vSphere Web Client contains a reflected cross-site scripting=0A=
vulnerability due to a lack of input sanitization. An attacker can=0A=
exploit this issue by tricking a victim into clicking a malicious=0A=
link.=0A=
=0A=
VMware would like to thank Matt Schmidt for reporting this issue to=0A=
us.=0A=
=0A=
The Common Vulnerabilities and Exposures project (cve.mitre.org) has=0A=
assigned the identifier CVE-2015-6931 to this issue.=0A=
=0A=
Column 4 of the following table lists the action required to=0A=
remediate the vulnerability in each release, if a solution is=0A=
available.=0A=
=0A=
VMware Product Running Replace with/=0A=
Product Version on Apply Patch=0A=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D =3D=3D=3D=3D=3D=3D=3D =
=3D=3D=3D=3D=3D=3D=3D =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=0A=
vCenter Server 6.0 Any not affected=0A=
vCenter Server 5.5 Any 5.5 U2d *=0A=
vCenter Server 5.1 Any 5.1 U3d *=0A=
vCenter Server 5.0 Any 5.0 U3g *=0A=
=0A=
* The client side component of the vSphere Web Client does not need=0A=
to be updated to remediate CVE-2015-6931. Updating the vCenter=0A=
Server is sufficient to remediate this issue.=0A=
=0A=
=0A=
4. Solution=0A=
=0A=
Please review the patch/release notes for your product and=0A=
version and verify the checksum of your downloaded file.=0A=
=0A=
vCenter Server=0A=
--------------=0A=
Downloads and Documentation:=0A=
https://www.vmware.com/go/download-vsphere=0A=
=0A=
=0A=
5. References=0A=
=0A=
http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2015-6931=0A=
=0A=
- ------------------------------------------------------------------------=
=0A=
=0A=
6. Change log=0A=
=0A=
2016-06-14 VMSA-2016-0009=0A=
Initial security advisory in conjunction with the release of VMware=0A=
vCenter Server 5.0 U3g on 2016-06-14.=0A=
=0A=
- ------------------------------------------------------------------------=
=0A=
=0A=
7. Contact=0A=
=0A=
E-mail list for product security notifications and announcements:=0A=
http://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce=0A=
=0A=
This Security Advisory is posted to the following lists:=0A=
=0A=
security-announce at lists.vmware.com=0A=
bugtraq at securityfocus.com=0A=
fulldisclosure at seclists.org=0A=
=0A=
E-mail: security at vmware.com=0A=
PGP key at: https://kb.vmware.com/kb/1055=0A=
=0A=
VMware Security Advisories=0A=
http://www.vmware.com/security/advisories=0A=
=0A=
Consolidated list of VMware Security Advisories=0A=
http://kb.vmware.com/kb/2078735=0A=
=0A=
VMware Security Response Policy=0A=
https://www.vmware.com/support/policies/security_response.html=0A=
=0A=
VMware Lifecycle Support Phases=0A=
https://www.vmware.com/support/policies/lifecycle.html=0A=
=0A=
Twitter=0A=
https://twitter.com/VMwareSRC=0A=
=0A=
Copyright 2016 VMware Inc. All rights reserved.=0A=
=0A=
-----BEGIN PGP SIGNATURE-----=0A=
Version: PGP Desktop 9.8.3 (Build 4028)=0A=
Charset: utf-8=0A=
=0A=
wj8DBQFXYOczDEcm8Vbi9kMRApfPAJ0Urm1NrLwTbkY0vsGeXQtS0kWDZQCgmYPj=0A=
dGcJx5HCyLJCiIz/FCMpGIU=3D=0A=
=3DFYiK=0A=
-----END PGP SIGNATURE-----=0A=