CVE ID | CVE-2016-7087 |
CVSS SCORE | 5.8, AV:N/AC:M/Au:N/C:P/I:P/A:N |
AFFECTED VENDORS |
VMware |
AFFECTED PRODUCTS |
Horizon View |
VULNERABILITY DETAILS |
The specific flaw exists within the loggerBean service. The loadConfig method does not properly sanitize the path supplied. An attacker can leverage this vulnerability to disclose arbitrary files from the system. |
ADDITIONAL DETAILS |
VMware has issued an update to correct this vulnerability. More details can be found at:
http://www.vmware.com/security/advisories/VMSA-2016-0015.html |
DISCLOSURE TIMELINE |
|
CREDIT | Mike Arnold (Bruk0ut) |