CVE-2016-2076
published 2016-04-15CVE-2016-2076: Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity…
PriorityP434high7.6CVSS 3.0
AVNACLPRNUIRSUCHILAL
EPSS
1.40%
69.4th percentile
Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2.4.1 mishandles session content, which allows remote attackers to hijack sessions via a crafted web site.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vcenter_server | <= 6.0 | — |
| vmware | vcenter_server | — | — |
| vmware | vcloud_automation_identity_appliance | — | — |
| vmware | vcloud_director | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vrealize | — | — |
| vmware | vmware_vsphere | — | — |
CVSS provenance
nvdv3.07.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8wg8-9xg9-58m4: Client Integration Plugin (CIP) in VMware vCenter Server 5
ghsa_unreviewed·2022-05-14
CVE-2016-2076 [HIGH] CWE-287 GHSA-8wg8-9xg9-58m4: Client Integration Plugin (CIP) in VMware vCenter Server 5
Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2.4.1 mishandles session content, which allows remote attackers to hijack sessions via a crafted web site.
VMware
VMware product updates address a critical security issue in the VMware Client Integration Plugin
vendor_vmware·2016-04-14·CVSS 7.6
CVE-2016-2076 [HIGH] VMware product updates address a critical security issue in the VMware Client Integration Plugin
VMSA-2016-0004: VMware product updates address a critical security issue in the VMware Client Integration Plugin
a. Critical VMware Client Integration Plugin incorrect session handling The VMware Client Integration Plugin does not handle session content in a safe way. This may allow for a Man in the Middle attack or Web session hijacking in case the user of the vSphere Web Client visits a malicious Web site. The vulnerability is present in versions of CIP that shipped with: - vCenter Server 6.0 (any 6.0 version prior to 6.0 U2) - vCenter Server 5.5 U3a, U3b, U3c - vCloud Director 5.5.5 - vRealize Automation Identity Appliance 6.2.4 In order to remediate the issue, both the server side (i.e. vCenter Server, vCloud Director, and vRealize Automation Identity Appliance) and the client side (i
Red Hat
xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
vendor_redhat·2016-03-24·CVSS 4.3
CVE-2016-3158 [MEDIUM] xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.
Statement: This issue does not affect the Xen hypervisor packages as shipped with Red Hat Enterprise Linux 5.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Red Hat
xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
vendor_redhat·2016-03-24·CVSS 4.3
CVE-2016-3159 [MEDIUM] xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.
Statement: This issue does not affect the Xen hypervisor packages as shipped with Red Hat Enterprise Linux 5.
Package: xen (Red Hat Enterprise Linux 5) - Not affected
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securitytracker.com/id/1035570http://www.securitytracker.com/id/1035571http://www.securitytracker.com/id/1035572http://www.vmware.com/security/advisories/VMSA-2016-0004.htmlhttp://www.securitytracker.com/id/1035570http://www.securitytracker.com/id/1035571http://www.securitytracker.com/id/1035572http://www.vmware.com/security/advisories/VMSA-2016-0004.html
2016-04-15
Published