CVE-2016-7458
Summary
| CVE | CVE-2016-7458 |
|---|---|
| State | PUBLISHED |
| Assigner | vmware |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-12-29 09:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. |
Risk And Classification
Primary CVSS: v3.0 5.8 MEDIUM from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
EPSS: 0.004490000 probability, percentile 0.636850000 (date 2026-05-11)
Problem Types: CWE-611 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 5.8 | MEDIUM | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N |
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:P/I:N/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
ChangedConfidentiality
LowIntegrity
NoneAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vmware | Vsphere Client | 5.5 | All | All | All |
| Application | Vmware | Vsphere Client | 5.5 | u1 | All | All |
| Application | Vmware | Vsphere Client | 5.5 | u2 | All | All |
| Application | Vmware | Vsphere Client | 5.5 | u3a | All | All |
| Application | Vmware | Vsphere Client | 5.5 | u3b | All | All |
| Application | Vmware | Vsphere Client | 6.0 | All | All | All |
| Application | Vmware | Vsphere Client | 6.0 | 2 | All | All |
| Application | Vmware | Vsphere Client | 6.0 | 2m | All | All |
| Application | Vmware | Vsphere Client | 6.0 | a | All | All |
| Application | Vmware | Vsphere Client | 6.0 | b | All | All |
| Application | Vmware | Vsphere Client | 6.0 | u1 | All | All |
| Application | Vmware | Vsphere Client | 6.0 | u1b | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VMSA-2016-0022 | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Vendor Advisory |
| VMware vSphere Client XML External Entity Processing Flaw Lets Remote Users Obtain Potentially Sensitive Information - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| VMware vSphere Client CVE-2016-7458 XML External Entity Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.