HIGH
The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e
Published Nov 17, 2017
7.5
HIGHCVSS 3.0
EPSS 1.24%
Description
The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRLF injection issues due to improper neutralization of URLs. An attacker may exploit these issues by sending a POST request with modified headers towards internal services leading to information disclosure.
Affected products
-
- Version 5.5 prior to 5.5 U3fStatusaffectedConstraints-
- Version 6.0 prior to 6.0 U3cStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| VMware | vSphere Web Client | n/a |
|
OR
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 5.5
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
- 6.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (3)
- http://www.securityfocus.com/bid/101785 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039759 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://www.vmware.com/security/advisories/VMSA-2017-0017.html x_refsource_CONFIRMPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/101785 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id/1039759 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| https://www.vmware.com/security/advisories/VMSA-2017-0017.html | x_refsource_CONFIRMPatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner vmware
Published Nov 17, 2017
Updated Sep 17, 2024
Reserved Dec 26, 2016
Link CVE-2017-4928
CISA Vulnrichment
Updated n/a