CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.Referenceshttp://www.securitytracker.com/id/1036543http://www.securityfocus.com/bid/92324http://www.securitytracker.com/id/1036544http://www.securityfocus.com/archive/1/539128/100/0/threadedhttp://www.vmware.com/security/advisories/VMSA-2016-0010.htmlhttp://seclists.org/fulldisclosure/2016/Aug/38http://www.securitytracker.com/id/1036545http://packetstormsecurity.com/files/138211/VMware-vSphere-Hypervisor-ESXi-HTTP-Response-Injection.html