CVE-2016-2076
Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2.4.1 mishandles session content, which allows remote attackers to hijack…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2.4.1 mishandles session content, which allows remote attackers to hijack sessions via a crafted web site.
- CVSS 3.0
- 7.6 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
- EPSS
- 1.40% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- vmware/vcenter server · vmware/vcloud automation identity appliance · vmware/vcloud director
- Source
- cve@mitre.org
References
- http://www.securitytracker.com/id/1035570Third Party Advisory
- http://www.securitytracker.com/id/1035571Third Party Advisory
- http://www.securitytracker.com/id/1035572Third Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2016-0004.htmlVendor Advisory
- http://www.securitytracker.com/id/1035570Third Party Advisory
- http://www.securitytracker.com/id/1035571Third Party Advisory
- http://www.securitytracker.com/id/1035572Third Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2016-0004.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.