Total vulnerabilities in the database
Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2.4.1 mishandles session content, which allows remote attackers to hijack sessions via a crafted web site.
Software | From | Fixed in |
---|---|---|
vmware / vcenter_server | 5.5-u3c | 5.5-u3c.x |
vmware / vcloud_director | 5.5.5 | 5.5.5.x |
vmware / vcloud_automation_identity_appliance | 6.2.4 | 6.2.4.x |
vmware / vcenter_server | 5.5-3a | 5.5-3a.x |
vmware / vcenter_server | 5.5-3b | 5.5-3b.x |
vmware / vcenter_server | - | 6.0.x |