VMware vRealize Business cross-site scripting (CVE-2016-2075)
VMware vRealize Business cross-site scripting (CVE-2016-2075)
Release date:
Updated on:
Affected Systems:
VMWare vRealize Business Advanced 8.x <8.2.5
Description:
CVE (CAN) ID: CVE-2016-2075
VMware vRealize Program Group is a cloud management platform applicable to vSphere, other management programs, physical architecture and external cloud.
On Linux, VMware vRealize Business Advanced and Enterprise 8.x <8.2.5 have the cross-site scripting vulnerability. Authenticated remote users can inject arbitrary Web scripts or HTML.
<* Source: Lukasz Plonka
*>
Suggestion:
Vendor patch:
VMWare
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.vmware.com/security/advisories/VMSA-2016-0003.html
This article permanently updates the link address: