back to article Critical VMware bug needs patching ASAP

Patch now, vAdmins: that's the message from VMware after it revealed a "critical security issue in the VMware Client Integration Plugin." Said plugin, VMware says, "does not handle session content in a safe way." "This may allow for a Man-in-the-Middle attack or Web session hijacking in case the user of the vSphere Web Client …

  1. Nate Amsden

    keep it

    (the web client)

    .NET client works fine. I hated the .NET client (as a linux user of 20 years) back when I first started using ESX over a decade ago, but this was more of a case of "be careful what you wish for", when the "improved" web client actually seems to be much worse than the existing thick client.

    Maybe by the time I do another major upgrade in vsphere (thinking 2018) the web client might be usable.

    Till then I use the .NET client on a XenApp (fundamentals) server.

    1. kryptylomese

      Re: keep it

      Are the alternatives to VMware not suitable for your needs?

      1. Anonymous Coward
        Anonymous Coward

        Re: keep it

        Except that the web and .net clients are not equal in functionality - some things only work using one client, and other things only work on the other.

        Bit of a shambles really.

        1. Spacedman

          Re: keep it

          I go through hell whenever I need to access VMs to install. Its not something I do often, so every time there's a new barrier. First there's the issue of getting the latest version of Flash working with Linux and whatever browser I find most stable at the time. Then there's the Client Integration Plugin to deal with. Which doesn't exist for Linux with vSphere 6.0 now. So I logged in remotely to a Windows box, tried the native client there, it didn't do things the Web client could do, so I was flipping between them, and after a day I did eventually have a new VM sitting there waiting to be virtually booted.

          At which point I noticed it didn't have a network interface. I couldn't add a network interface. At this point I sent an email to the cluster admins (because it smelt like a "we havent given you permission to create networks, but we're not going to give you an error message that explicit" situation) and I've heard nothing since.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like