Description
Directory traversal vulnerability in the Connection Server in VMware Horizon View 5.x before 5.3.7, 6.x before 6.2.3, and 7.x before 7.0.1 allows remote attackers to obtain sensitive information via unspecified vectors.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/93455
Patch, Vendor Advisory x_refsource_confirm
http://www.vmware.com/security/advisories/VMSA-2016-0015.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1036972
Scores
CVSS v3
5.3
EPSS
0.0239
EPSS Percentile
85.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-22
Status
published
Products (12)
vmware/horizon_view
5.0
vmware/horizon_view
5.0.1
vmware/horizon_view
5.1
vmware/horizon_view
5.1.3
vmware/horizon_view
5.2.0
vmware/horizon_view
5.3
vmware/horizon_view
6.0
vmware/horizon_view
6.0.2
vmware/horizon_view
6.1
vmware/horizon_view
6.1.1
... and 2 more
Published
Dec 29, 2016
Tracked Since
Feb 18, 2026