VMware vCenter Chargeback Manager ImageUploadServlet Arbitrary File Upload
Publish Date: 21 lipca 2015
Severity: : High
Advisory Date: 21 lipca 2015
DESCRIPTION
VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers to execute arbitrary code via unspecified vectors.
INFORMATION EXPOSURE
Apply associated Trend Micro DPI Rules.
SOLUTION
Trend Micro Deep Security DPI Rule Number: 1005647