VYPR

Vcloud Director

Sign in to watch

by VMware

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2016-2076Hig0.497.60.00Apr 15, 2016Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2.4.1 mishandles session content, which allows remote attackers to hijack sessions via a crafted web site.
CVE-2014-12110.000.00Jan 17, 2014Cross-site request forgery (CSRF) vulnerability in VMware vCloud Director 5.1.x before 5.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout.