VMware has updated vSphere third party libraries
Apply the missing patch(es).
a. vCenter Server Apache Struts Update The Apache Struts library is updated to address a security issue. This issue may lead to remote code execution after authentication. b. vCenter Server tc-server 2.9.5 / Apache Tomcat 7.0.52 updates tc-server has been updated to version 2.9.5 to address multiple security issues. This version of tc-server includes Apache Tomcat 7.0.52. c. Update to ESXi glibc package glibc is updated to address multiple security issues. d. vCenter and Update Manager, Oracle JRE 1.7 Update 55 Oracle has documented the CVE identifiers that are addressed in JRE 1.7.0 update 55 in the Oracle Java SE Critical Patch Update Advisory of April 2014
VMware vCenter Server 5.5 prior to Update 2 VMware vCenter Update Manager 5.5 prior to Update 2 VMware ESXi 5.5 without patch ESXi550-201409101-SG
Checks for missing patches.
Updated on 2015-03-25
CVE CVE-2013-0242, CVE-2013-1914, CVE-2013-4322, CVE-2013-4590, CVE-2014-0050, CVE-2014-0114
CVSS Base Score: 7.5
- VMSA-2012-0011 VMware Workstation, Player, Fusion, ESXi and ESX patches address security issues.
- VMSA-2012-0006 VMware ESXi and ESX address several security issues
- VMSA-2012-0009 VMware Workstation, Player, ESXi and ESX patches address critical security issues
- VMSA-2015-0001: VMware vCenter Server, ESXi, Workstation, Player, and Fusion updates address security issues
- VMSA-2011-0007 VMware ESXi and ESX Denial of Service and third party updates for Likewise components and ESX Service Console