CVE-2017-4928
published 2017-11-17CVE-2017-4928: The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRLF…
PriorityP339high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.24%
65.7th percentile
The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRLF injection issues due to improper neutralization of URLs. An attacker may exploit these issues by sending a POST request with modified headers towards internal services leading to information disclosure.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vsphere | — | — |
| vmware | vsphere_web_client | — | — |
| vmware | vsphere_web_client | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter Server update resolves LDAP DoS, SSRF and CRLF injection issues
vendor_vmware·2017-11-09·CVSS 7.5
CVE-2017-4927 [HIGH] VMware vCenter Server update resolves LDAP DoS, SSRF and CRLF injection issues
VMSA-2017-0017: VMware vCenter Server update resolves LDAP DoS, SSRF and CRLF injection issues
a. VMware vCenter Server LDAP Denial of Service (DoS). VMware vCenter Server doesn't correctly handle specially crafted LDAP network packets which may allow for remote DoS. VMware would like to thank Honggang Ren of Fortinet's FortiGuard Labs for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2017-4927 to this issue. Column 5 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available. VMware Product Product Version Running on Severity Replace with/ Apply Patch
CVEs: CVE-2017-4927, CVE-2017-4928, CVE-2017-4929
Affected products: VMware vCenter Server, vSp
GHSA
GHSA-hgcm-2jjw-4pr2: The flash-based vSphere Web Client (6
ghsa_unreviewed·2022-05-14
CVE-2017-4928 [HIGH] CWE-352 GHSA-hgcm-2jjw-4pr2: The flash-based vSphere Web Client (6
The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRLF injection issues due to improper neutralization of URLs. An attacker may exploit these issues by sending a POST request with modified headers towards internal services leading to information disclosure.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-11-17
Published