Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-7087


Directory traversal vulnerability in the Connection Server in VMware Horizon View 5.x before 5.3.7, 6.x before 6.2.3, and 7.x before 7.0.1 allows remote attackers to obtain sensitive information via unspecified vectors.


Published

2016-12-29T09:59:00.507

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 5.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application vmware horizon_view 5.0 Yes
Application vmware horizon_view 5.0.1 Yes
Application vmware horizon_view 5.1 Yes
Application vmware horizon_view 5.1.3 Yes
Application vmware horizon_view 5.2.0 Yes
Application vmware horizon_view 5.3 Yes
Application vmware horizon_view 6.0 Yes
Application vmware horizon_view 6.0.2 Yes
Application vmware horizon_view 6.1 Yes
Application vmware horizon_view 6.1.1 Yes
Application vmware horizon_view 6.2 Yes
Application vmware horizon_view 7.0 Yes
Operating System microsoft windows * No

References