← العودة للجدول
CVE-2016-7460
CVE-2016-7460 — The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 befor
📅 2016-12-29
🔴 Critical 🔥 No NVD DDoS VMware CVSS 9.1 🎯 EPSS 2.01%

📋 الوصف الكامل

The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

💻 الأنظمة المتأثرة

VMware vCenter

⚠️ نوع التهديد

DDoS

🔗 CVE ID

CVE-2016-7460

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2016-7460 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←