Description
VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create scheduled tasks may be able to manipulate the notification emails sent for scheduled tasks.
Problem types
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
Product status
8.0 before 8.0 U3g
7.0 before 7.0 U3w
9.x.x.x before 9.0.1.0
5.x before 5.2.2
4.5.x
5.x, 4.x, 3.x, 2.x
3.x, 2.x
9.x.x.x before 9.0.1.0
References
support.broadcom.com/...l/content/SecurityAdvisories/0/36150