VMWare products Multiple Vulnerabilities
Last Update Date:
23 Dec 2015
Release Date:
22 Dec 2015
3871
Views
RISK: Medium Risk
TYPE: Operating Systems - VM Ware
- Oracle JRE is updated in VMware products to address critical security issue that existed in earlier releases of Oracle JRE.
- VMware products that use Flex BlazeDS may be affected by a flaw the processing of XML External Entity (XXE) requests. A crafted XML request sent to the server could lead to information be disclosed.
Impact
- Cross-Site Scripting
- Security Restriction Bypass
- Information Disclosure
- Data Manipulation
System / Technologies affected
Please refer to the following links for the full list of affected products:
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Vendor has issued patches
Vulnerability Identifier
Source
Related Link
Share with