CVE-2017-4928
17.11.2017, 14:29
The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRLF injection issues due to improper neutralization of URLs. An attacker may exploit these issues by sending a POST request with modified headers towards internal services leading to information disclosure.
Vendor | Product | Version |
---|---|---|
vmware | vcenter_server | 5.5 |
vmware | vcenter_server | 5.5:1 |
vmware | vcenter_server | 5.5:1a |
vmware | vcenter_server | 5.5:1b |
vmware | vcenter_server | 5.5:1c |
vmware | vcenter_server | 5.5:2 |
vmware | vcenter_server | 5.5:2b |
vmware | vcenter_server | 5.5:2d |
vmware | vcenter_server | 5.5:2e |
vmware | vcenter_server | 5.5:3 |
vmware | vcenter_server | 5.5:3a |
vmware | vcenter_server | 5.5:3b |
vmware | vcenter_server | 5.5:3d |
vmware | vcenter_server | 5.5:3e |
vmware | vcenter_server | 5.5:b |
vmware | vcenter_server | 5.5:c |
vmware | vcenter_server | 6.0 |
vmware | vcenter_server | 6.0:1 |
vmware | vcenter_server | 6.0:1b |
vmware | vcenter_server | 6.0:2 |
vmware | vcenter_server | 6.0:2a |
vmware | vcenter_server | 6.0:2m |
vmware | vcenter_server | 6.0:3 |
vmware | vcenter_server | 6.0:3a |
vmware | vcenter_server | 6.0:3b |
vmware | vcenter_server | 6.0:a |
vmware | vcenter_server | 6.0:b |
𝑥
= Vulnerable software versions
Common Weakness Enumeration