Skip to main content

VMWare products Multiple Vulnerabilities

Last Update Date: 23 Dec 2015 Release Date: 22 Dec 2015 3045 Views

RISK: Medium Risk

TYPE: Operating Systems - VM Ware

TYPE: VM Ware
  • Oracle JRE is updated in VMware products to address critical security issue that existed in earlier releases of Oracle JRE.
  • VMware products that use Flex BlazeDS may be affected by a flaw the processing of XML External Entity (XXE) requests. A crafted XML request sent to the server could lead to information be disclosed.

 


Impact

  • Cross-Site Scripting
  • Security Restriction Bypass
  • Information Disclosure
  • Data Manipulation

System / Technologies affected

Please refer to the following links for the full list of affected products:

 


Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Vendor has issued patches

Vulnerability Identifier


Source


Related Link