CVE-2016-2076

Severity
7.6HIGH
EPSS
0.4%
top 36.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 15
Latest updateMay 14

Description

Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2.4.1 mishandles session content, which allows remote attackers to hijack sessions via a crafted web site.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:LExploitability: 2.8 | Impact: 4.7

Affected Packages3 packages

🔴Vulnerability Details

2
GHSA
GHSA-8wg8-9xg9-58m4: Client Integration Plugin (CIP) in VMware vCenter Server 52022-05-14
CVEList
CVE-2016-2076: Client Integration Plugin (CIP) in VMware vCenter Server 52016-04-15

📋Vendor Advisories

2
Red Hat
xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)2016-03-24
Red Hat
xen: AMD FPU FIP/FDP/FOP leak workaround broken (XSA-172)2016-03-24
CVE-2016-2076 (HIGH CVSS 7.6) | Client Integration Plugin (CIP) in | cvebase.io