VMware vCenter Server CRLF Injection and Server Side Request Forgery Security Bypass Vulnerabilities
BID:101785
CVE-2017-4928 |Info
VMware vCenter Server CRLF Injection and Server Side Request Forgery Security Bypass Vulnerabilities
| Bugtraq ID: | 101785 |
| Class: | Design Error |
| CVE: |
CVE-2017-4928 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 09 2017 12:00AM |
| Updated: | Dec 19 2017 10:00PM |
| Credit: | ricterzheng @ Tencent Yunding Lab |
| Vulnerable: |
VMWare vCenter Server 6.0 VMWare vCenter Server 5.5 |
| Not Vulnerable: |
VMWare vCenter Server 6.0 U3c VMWare vCenter Server 5.5 U3f |
Discussion
VMware vCenter Server CRLF Injection and Server Side Request Forgery Security Bypass Vulnerabilities
VMware vCenter Server is prone to a CRLF-injection vulnerability and a security-bypass vulnerability.
An attacker may exploit these issues to obtain sensitive information or to bypass certain security restrictions and perform unauthorized actions. This may lead to further attacks.
VMware vCenter Server is prone to a CRLF-injection vulnerability and a security-bypass vulnerability.
An attacker may exploit these issues to obtain sensitive information or to bypass certain security restrictions and perform unauthorized actions. This may lead to further attacks.
References
VMware vCenter Server CRLF Injection and Server Side Request Forgery Security Bypass Vulnerabilities
References:
References: