← Back

CVE-2017-4928

nvd nist
Published: Nov 17, 2017Modified: May 13, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRLF injection issues due to improper neutralization of URLs. An attacker may exploit these issues by sending a POST request with modified headers towards internal services leading to information disclosure.

Affected (27)

1 product
Vcenter Server
Configuration A
27 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
Version 5.5
Version 5.5 1
Version 5.5 1a
Version 5.5 1b
Version 5.5 1c
Version 5.5 2
Version 5.5 2b
Version 5.5 2d
Version 5.5 2e
Version 5.5 3
Version 5.5 3a
Version 5.5 3b
Version 5.5 3d
Version 5.5 3e
Version 5.5 b
Version 5.5 c
Version 6.0
Version 6.0 1
Version 6.0 1b
Version 6.0 2
Version 6.0 2a
Version 6.0 2m
Version 6.0 3
Version 6.0 3a
Version 6.0 3b
Version 6.0 a
Version 6.0 b

References (6)

Source: security@vmware.com
Third Party AdvisoryVDB Entry
Source: security@vmware.com
Third Party AdvisoryVDB Entry
Source: security@vmware.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.