← Vulnerability feed

Vulnerability record · CVE-2016-7460 · published 29 December 2016

CVE-2016-7460: Vmware vrealize automation xml external entity (xxe) vulnerability

Vmware · Vrealize Automation

The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

9.1 CVSS 3.0 Critical EPSS 2.1% · top 18.6% CWE-611 · XML external entity (XXE)
9.1CVSS 3.0 base score, v2 6.4
2.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-7460 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-22954VMware Workspace ONE Access and Identity Manager server-side template injection RCEVMware Workspace ONE Access and Identity Manager are affected by a server-side template injection flaw that allows remote code execution. A network-r…KEVEPSS 100%analysed7.8CVE-2022-22960VMware Workspace ONE Access and related products local privilege escalationVMware Workspace ONE Access, Identity Manager, vRealize Automation and related products ship support scripts with incorrect permission assignments (C…KEVEPSS 36%analysed9.8CVE-2022-22972VMware Workspace ONE Access and related products authentication bypassVMware Workspace ONE Access, Identity Manager, and vRealize Automation contain an authentication bypass affecting local domain users. A remote attack…EPSS 56%analysed9.8CVE-2022-22955Vmware identity manager vulnerabilityVMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious …EPSS 7.9%9.8CVE-2022-22956VMware Workspace ONE Access OAuth2 authentication bypassVMware Workspace ONE Access (and related Identity Manager and vRealize Automation deployments) contains an authentication bypass in the OAuth2 ACS fr…EPSS 50%analysed9.8CVE-2018-6959Vmware vrealize automation vulnerabilityVMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs. Exploitation of this issue may lead to the h…EPSS 2.0%9.8CVE-2017-4947Vmware vrealize automation deserialization of untrusted data vulnerabilityVMware vRealize Automation (7.3 and 7.2) and vSphere Integrated Containers (1.x before 1.3) contain a deserialization vulnerability via Xenon. Succes…EPSS 8.6%9.8CVE-2016-5336Vmware vrealize automation vulnerabilityVMware vRealize Automation 7.0.x before 7.1 allows remote attackers to execute arbitrary code via unspecified vectors.EPSS 2.9%

Source: NIST National Vulnerability Database (record CVE-2016-7460), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.