NEW VMSA-2016-0003 – VMware vRealize Automation and vRealize Business Advanced and Enterprise address Cross-Site Scripting (XSS) issues

VMware vRealize Automation and vRealize Business Advanced and Enterprise address Cross-Site Scripting (XSS) issues.

VMware Security Advisory
Advisory ID: VMSA-2016-0003
Synopsis: VMware vRealize Automation and vRealize Business Advanced and Enterprise address Cross-Site Scripting (XSS) issues.
Issue date: 2016-03-15
Updated on: 2016-03-15 (Initial Advisory)
CVE numbers: CVE-2015-2344, CVE-2016-2075
1. Summary
VMware vRealize Automation and vRealize Business Advanced and Enterprise address Cross-Site Scripting (XSS) issues.
2. Relevant Releases
VMware vRealize Automation 6.x prior to 6.2.4
VMware vRealize Business Advanced and Enterprise 8.x prior to 8.2.5
3. Problem Description
a. Important Stored Cross-Site Scripting (XSS) issue in VMware vRealize AutomationVMware vRealize Automation contains a vulnerability that may allow for a Stored Cross-Site Scripting (XSS) attack. Exploitation of this issue may lead to the compromise of a vRA user’s client workstation.

VMware would like to thank would like to thank Lukasz Plonka for reporting this issue to us.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2015-2344 to this issue.

Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available.

VMware Product Running Replace with/
Product Version on Apply Patch
VMware vRealize Automation 7.x Linux Not Affected
VMware vRealize Automation 6.x Linux 6.2.4
VMware vRealize Automation 5.x Windows Not Affected

b. Important Stored Cross-Site Scripting (XSS) issue in vRealize Business Advanced and Enterprise

VMware vRealize Business Advanced and Enterprise contains a vulnerability that may allow for a Stored Cross-Site Scripting (XSS) attack. Exploitation of this issue may lead to the compromise of a vRB user’s client workstation.

VMware would like to thank Alvaro Trigo Martin de Vidales of Deloitte Spain for reporting this issue to us.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2016-2075 to this issue.

Column 4 of the following table lists the action required to remediate the vulnerability in each release, if a solution is available.

VMware Product Running Replace with/
Product Version on Apply Patch
VMware vRealize Business Advanced and Enterprise 8.x Linux 8.2.5
VMware vRealize Business Advanced and Enterprise 7.x Linux Not Affected
VMware vRealize Business Advanced and Enterprise 6.x Linux Not Affected
4. Solution

Please review the patch/release notes for your product and version and verify the checksum of your downloaded file.

VMware vRealize Automation 6.2.4
Downloads and Documentation

VMware vRealize Business Advanced and Enterprise 8.2.5
Downloads and Documentation

6. Change log
2016-03-15 VMSA-2016-0003 Initial security advisory in conjunction with the release of VMware vRealize Automation 6.2.4 and VMware vRealize Business Advanced and Enterprise 8.2.5 on 2016-03-15.

Created on March 15, 2016 by Rick Scherer

Posted under Alert.

This blog has 28,084 views.

Tags: , , , ,

1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading...

Leave a Comment

Name (required)

Email (required)

Website

Comments

More Blog Post