Session Hijacking Vulnerability in VMware vCenter Server and vCloud Director
CVE-2016-2076
7.6HIGH
Key Information:
- Vendor
- Vmware
- Vendor
- CVE Published:
- 15 April 2016
Summary
The Client Integration Plugin (CIP) in VMware vCenter Server, vCloud Director, and vRealize Automation Identity Appliance has a flaw that mishandles session content. This vulnerability allows an attacker to hijack a user's session by exploiting crafted web content, potentially leading to unauthorized access and exposure of sensitive information.
References
CVSS V3.1
Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved