CVE-2016-2075

MEDIUM

Vmware Vrealize Business Advanced And Enterprise - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in VMware vRealize Business Advanced and Enterprise 8.x before 8.2.5 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Scores

CVSS v3 5.4
EPSS 0.0010
EPSS Percentile 26.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Classification

CWE
CWE-79
Status draft

Affected Products (9)

vmware/vrealize_business_advanced_and_enterprise
vmware/vrealize_business_advanced_and_enterprise
vmware/vrealize_business_advanced_and_enterprise
vmware/vrealize_business_advanced_and_enterprise
vmware/vrealize_business_advanced_and_enterprise
vmware/vrealize_business_advanced_and_enterprise
vmware/vrealize_business_advanced_and_enterprise
vmware/vrealize_business_advanced_and_enterprise
vmware/vrealize_business_advanced_and_enterprise

Timeline

Published Mar 16, 2016
Tracked Since Feb 18, 2026