VMware vSphere Product Multiple Vulnerabilities
Last Update Date:
8 Dec 2014 12:34
Release Date:
8 Dec 2014
3801
Views
RISK: Medium Risk
TYPE: Operating Systems - VM Ware
Multiple vulnerabilities have been identified in VMware vSphere product, which can be exploited by malicious people to conduct spoofing attacks, bypass certain security restrictions, and cause a DoS (Denial of Service).
Impact
- Cross-Site Scripting
- Denial of Service
- Security Restriction Bypass
- Spoofing
System / Technologies affected
- VMware vCenter Server Appliance 5.1 Prior to Update 3
- VMware vCenter Server 5.5 prior to Update 2
- VMware vCenter Server 5.1 prior to Update 3
- VMware vCenter Server 5.0 prior to Update 3c
- VMware ESXi 5.1 without patch ESXi510-201412101-SG
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Apply vendor patch
Vulnerability Identifier
- CVE-2014-3797
- CVE-2014-8371
- CVE-2013-2877
- CVE-2014-0191
- CVE-2014-0015
- CVE-2014-0138
- CVE-2013-1752
- CVE-2013-4238
Source
Related Link
Share with