Total vulnerabilities in the database
VMware vCenter Server (6.7 before 6.7u3, 6.6 before 6.5u3k) contains a session hijack vulnerability in the vCenter Server Appliance Management Interface update function due to a lack of certificate validation. A malicious actor with network positioning between vCenter Server and an update repository may be able to perform a session hijack when the vCenter Server Appliance Management Interface is used to download vCenter updates.
Software | From | Fixed in |
---|---|---|
vmware / vcenter_server | 6.5-f | 6.5-f.x |
vmware / vcenter_server | 6.5-e | 6.5-e.x |
vmware / vcenter_server | 6.5-d | 6.5-d.x |
vmware / vcenter_server | 6.5-c | 6.5-c.x |
vmware / vcenter_server | 6.5-b | 6.5-b.x |
vmware / vcenter_server | 6.5-a | 6.5-a.x |
vmware / vcenter_server | 6.7-d | 6.7-d.x |
vmware / vcenter_server | 6.7-b | 6.7-b.x |
vmware / vcenter_server | 6.7-a | 6.7-a.x |
vmware / vcenter_server | 6.5 | 6.5.x |
vmware / vcenter_server | 6.7 | 6.7.x |
vmware / cloud_foundation | 3.0 | 3.9 |
vmware / vcenter_server | 6.5-update1 | 6.5-update1.x |
vmware / vcenter_server | 6.5-update1c | 6.5-update1c.x |
vmware / vcenter_server | 6.5-update1b | 6.5-update1b.x |
vmware / vcenter_server | 6.5-update3 | 6.5-update3.x |
vmware / vcenter_server | 6.5-update3d | 6.5-update3d.x |
vmware / vcenter_server | 6.5-update1d | 6.5-update1d.x |
vmware / vcenter_server | 6.5-update1e | 6.5-update1e.x |
vmware / vcenter_server | 6.5-update1g | 6.5-update1g.x |
vmware / vcenter_server | 6.5-update2 | 6.5-update2.x |
vmware / vcenter_server | 6.5-update2b | 6.5-update2b.x |
vmware / vcenter_server | 6.5-update2c | 6.5-update2c.x |
vmware / vcenter_server | 6.5-update2d | 6.5-update2d.x |
vmware / vcenter_server | 6.5-update2g | 6.5-update2g.x |
vmware / vcenter_server | 6.7-update1 | 6.7-update1.x |
vmware / vcenter_server | 6.7-update1b | 6.7-update1b.x |
vmware / vcenter_server | 6.7-update2 | 6.7-update2.x |
vmware / vcenter_server | 6.7-update2a | 6.7-update2a.x |
vmware / vcenter_server | 6.7-update2c | 6.7-update2c.x |