Session Hijacking Vulnerability in VMware vCenter Server and vCloud Director
CVE-2016-2076

7.6HIGH

Key Information:

Summary

The Client Integration Plugin (CIP) in VMware vCenter Server, vCloud Director, and vRealize Automation Identity Appliance has a flaw that mishandles session content. This vulnerability allows an attacker to hijack a user's session by exploiting crafted web content, potentially leading to unauthorized access and exposure of sensitive information.

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.