CVE-2016-2076
HIGHVmware Vcenter Server < 6.0 - Authentication Bypass
Title source: ruleDescription
Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2.4.1 mishandles session content, which allows remote attackers to hijack sessions via a crafted web site.
Scores
CVSS v3
7.6
EPSS
0.0044
EPSS Percentile
62.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
Classification
CWE
CWE-287
Status
draft
Affected Products (6)
vmware/vcenter_server
< 6.0
vmware/vcenter_server
vmware/vcenter_server
vmware/vcenter_server
vmware/vcloud_automation_identity_appliance
vmware/vcloud_director
Timeline
Published
Apr 15, 2016
Tracked Since
Feb 18, 2026