Lucene search

K
vmwareVMwareVMSA-2016-0004
HistoryApr 14, 2016 - 12:00 a.m.

VMware product updates address a critical security issue in the VMware Client Integration Plugin

2016-04-1400:00:00
www.vmware.com
30

0.004 Low

EPSS

Percentile

72.9%

a. Critical VMware Client Integration Plugin incorrect session handling The VMware Client Integration Plugin does not handle session content in a safe way. This may allow for a Man in the Middle attack or Web session hijacking in case the user of the vSphere Web Client visits a malicious Web site. The vulnerability is present in versions of CIP that shipped with:

0.004 Low

EPSS

Percentile

72.9%

Related for VMSA-2016-0004