Arbitrary Command Execution Vulnerabilities (CVE-2015-6934) across VMware Products)
Arbitrary Command Execution Vulnerabilities (CVE-2015-6934) across VMware Products)
Release date:
Updated on:
Affected Systems:
VMWare VMware vCenter Orchestrator 5.x
VMWare vRealize Operations 6.x
VMWare vCenter Application Discovery Manager (vADM) 7.x
Description:
CVE (CAN) ID: CVE-2015-6934
VMware vCenter Orchestrator is an application that automatically manages tasks.
VMware vRealize Orchestrator 6.x, vCenter Orchestrator 5.x, vRealize Operations 6.x, vCenter Operations 5.x, vCenter Application disadm Manager (vADM) 7. x security vulnerabilities exist in serialized object interfaces. Remote attackers can exploit this vulnerability to execute arbitrary commands by constructing serialized Java objects.
<* Source: VMware (vmware-security-alert@vmware.com)
Link: http://www.vmware.com/security/advisories/VMSA-2015-0009.html
*>
Suggestion:
Vendor patch:
VMWare
------
VMWare has released a Security Bulletin (VMSA-2015-0009) and patches for this:
VMSA-2015-0009: VMware product updates address a critical deserialization vulnerability
Link: http://www.vmware.com/security/advisories/VMSA-2015-0009.html
Patch download: http://kb.vmware.com/kb/2141244
This article permanently updates the link address: