Posts

Showing posts with the label fix

CVE-2020-4006 - Command Injection

Important alert on CVE-2020-4006 as document here which has a maximum CVSSv3 base score of 7.2 which was discovered on 23rd Nov 2020. A workaround was first provided to mitigate this risk now a fix is available. In summary, this vulnerability allows an attacker who have got hold of the configuration admin account for the affected products to execute commands. The configuration admin account password is set during time of deployment. Affected Products: VMware Workspace One Access (Access) VMware Workspace One Access Connector (Access Connector) VMware Identity Manager (vIDM) VMware Identity Manager Connector (vIDM Connector) VMware Cloud Foundation vRealize Suite Lifecycle Manager  If you are using any of the products affected, do take sometime to remediate this as soon as possible.

vSphere 6.0 Web Client Integration Plug-in Bug Fix

Image
So the new vSphere 6.0 has release, what is great on one of the functionality is the web client.  It has always be crawling since it was introduced in vSphere 5.0.  In vSphere 6.0, it was promised with great performance improvement and it was great! On day 0 daily operations activity, accessing the VM console is essential and often used.  When you launch the vSphere Web Client, you will be at the login page.  Below you will see the link to download the Client Integration Plug-in as shown below: After installing, you will be able to access the VM console after logging in.  Upon login, you will see the screen below when a VM is selected: Above you see the screenshot taken from Hands-on-Lab.  To access a VM console you will have selected the VM and on the right you will see the above.  Clicking on "Launch Console", will launch the VM console in a new tab\window of your browser.  However this link is invalid!  So how are you going to ...