CVE-2016-5332
published 2016-08-31CVE-2016-5332: Directory traversal vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.6.0 allows remote attackers to read arbitrary files via unspecified…
PriorityP434medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
2.96%
85.6th percentile
Directory traversal vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.6.0 allows remote attackers to read arbitrary files via unspecified vectors.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vrealize_log_insight | — | — |
| vmware | vrealize_log_insight | — | — |
| vmware | vrealize_log_insight | — | — |
| vmware | vrealize_log_insight | — | — |
| vmware | vrealize_log_insight | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Photon OS OVA default public ssh key
vendor_vmware·2016-08-15·CVSS 5.3
CVE-2016-5332 [MEDIUM] VMware Photon OS OVA default public ssh key
VMSA-2016-0012: VMware Photon OS OVA default public ssh key
a. VMware Photon OS OVA default public ssh key A public ssh key used in the Photon OS build environment was inadvertently left in the original Photon OS 1.0 OVAs. This issue would have allowed anyone with the corresponding private key to access any Photon OS system built from the original 1.0 OVAs. The issue was discovered internally and the original OVAs have been replaced by updated OVAs. All instances of the corresponding private key have been deleted within VMware. Customers that have downloaded a Photon OS 1.0 OVA before August 14, 2016 should review the Photon OS OVAs release notes for the workaround or should download a new OVA and replace all existing instances with new instances built from the updated Photon OS 1.0 OVAs.
VMware
vRealize Log Insight update addresses directory traversal vulnerability.
vendor_vmware·2016-08-11·CVSS 5.3
CVE-2016-5332 [MEDIUM] vRealize Log Insight update addresses directory traversal vulnerability.
VMSA-2016-0011: vRealize Log Insight update addresses directory traversal vulnerability.
vRealize Log Insight contains a vulnerability that may allow for a directory traversal attack. Exploitation of this issue may lead to a partial information disclosure. There are no known workarounds for this issue. VMware would like to thank Peter Nelson, Security Engineer at WakeMed Health & Hospitals for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2016-5332 to this issue. Column 5 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Severity Replace with/ Apply Patch*
CVEs: CVE-2016-5332
GHSA
GHSA-qhfq-g7p8-w39w: Directory traversal vulnerability in VMware vRealize Log Insight 2
ghsa_unreviewed·2022-05-17
CVE-2016-5332 [MEDIUM] CWE-22 GHSA-qhfq-g7p8-w39w: Directory traversal vulnerability in VMware vRealize Log Insight 2
Directory traversal vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.6.0 allows remote attackers to read arbitrary files via unspecified vectors.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-08-31
Published