CVE-2016-7458
Summary
| CVE | CVE-2016-7458 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-12-29 09:59:00 UTC |
| Updated | 2017-07-28 01:29:00 UTC |
| Description | VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. |
Risk And Classification
Problem Types: CWE-611
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vmware | Vsphere Client | 5.5 | All | All | All |
| Application | Vmware | Vsphere Client | 5.5 | u1 | All | All |
| Application | Vmware | Vsphere Client | 5.5 | u2 | All | All |
| Application | Vmware | Vsphere Client | 5.5 | u3a | All | All |
| Application | Vmware | Vsphere Client | 5.5 | u3b | All | All |
| Application | Vmware | Vsphere Client | 6.0 | All | All | All |
| Application | Vmware | Vsphere Client | 6.0 | 2 | All | All |
| Application | Vmware | Vsphere Client | 6.0 | 2m | All | All |
| Application | Vmware | Vsphere Client | 6.0 | a | All | All |
| Application | Vmware | Vsphere Client | 6.0 | b | All | All |
| Application | Vmware | Vsphere Client | 6.0 | u1 | All | All |
| Application | Vmware | Vsphere Client | 6.0 | u1b | All | All |
| Application | Vmware | Vsphere Client | 5.5 | All | All | All |
| Application | Vmware | Vsphere Client | 5.5 | u1 | All | All |
| Application | Vmware | Vsphere Client | 5.5 | u2 | All | All |
| Application | Vmware | Vsphere Client | 5.5 | u3a | All | All |
| Application | Vmware | Vsphere Client | 5.5 | u3b | All | All |
| Application | Vmware | Vsphere Client | 6.0 | All | All | All |
| Application | Vmware | Vsphere Client | 6.0 | 2 | All | All |
| Application | Vmware | Vsphere Client | 6.0 | 2m | All | All |
| Application | Vmware | Vsphere Client | 6.0 | a | All | All |
| Application | Vmware | Vsphere Client | 6.0 | b | All | All |
| Application | Vmware | Vsphere Client | 6.0 | u1 | All | All |
| Application | Vmware | Vsphere Client | 6.0 | u1b | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VMware vSphere Client XML External Entity Processing Flaw Lets Remote Users Obtain Potentially Sensitive Information - SecurityTracker | SECTRACK | www.securitytracker.com | |
| VMSA-2016-0022 | CONFIRM | www.vmware.com | Vendor Advisory |
| VMware vSphere Client CVE-2016-7458 XML External Entity Information Disclosure Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.