Release date: 2012-03-16
Updated on: 2012-03-19
Affected Systems:
VMWare vSphere Client 5.x
VMWare vSphere Client 4.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52525
CVE (CAN) ID: CVE-2012-1512
VMware vCenter is a powerful centralized management component for hosts and virtual machines in the VMware vSphere suite. VMware vSphere Client is used to connect to and manage vSphere servers, such as creating, managing, and configuring virtual machines.
When viewing specific log records, some inputs are used without proper filtering. Attackers can insert arbitrary HTML and script code and execute them in browser sessions when viewing these malicious data.
<* Source: Edward Torkington
Link: http://secunia.com/advisories/48387/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
VMWare
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.vmware.com/security/