CVE
- Id
- 94280
- CVE No.
- CVE-2016-7460
- Status
- Candidate
- Description
- The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
- Phase
- Assigned (20160909)
- Votes
- None (candidate not yet proposed)
- Comments