CVE-2008-2101
published 2008-09-03CVE-2008-2101: The VMware Consolidated Backup (VCB) command-line utilities in VMware ESX 3.0.1 through 3.0.3 and ESX 3.5 place a password on the command line, which allows…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.38%
30.6th percentile
The VMware Consolidated Backup (VCB) command-line utilities in VMware ESX 3.0.1 through 3.0.3 and ESX 3.5 place a password on the command line, which allows local users to obtain sensitive information by listing the process.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mfg6-9jcc-433j: The VMware Consolidated Backup (VCB) command-line utilities in VMware ESX 3
ghsa_unreviewed·2022-05-01
CVE-2008-2101 [LOW] CWE-200 GHSA-mfg6-9jcc-433j: The VMware Consolidated Backup (VCB) command-line utilities in VMware ESX 3
The VMware Consolidated Backup (VCB) command-line utilities in VMware ESX 3.0.1 through 3.0.3 and ESX 3.5 place a password on the command line, which allows local users to obtain sensitive information by listing the process.
VMware
Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX, VMware VCB address information disclosure, privilege escalation and other security issues.
vendor_vmware·2008-08-29·CVSS 1.9
CVE-2007-5269 [LOW] Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX, VMware VCB address information disclosure, privilege escalation and other security issues.
VMSA-2008-0014: Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX, VMware VCB address information disclosure, privilege escalation and other security issues.
I Security Issues a. Setting ActiveX killbit Starting from this release, VMware has set the killbit on its ActiveX controls. Setting the killbit ensures that ActiveX controls cannot run in Internet Explorer (IE), and avoids Microsoft KB article 240797 and the related references on this topic. Security vulnerabilities have been reported for ActiveX controls provided by VMware when run in IE. Under specific circumstances, exploitation of these ActiveX controls might result in denial-of- service or can allow running of arbitrary code when the user browses a malicious Web site or opens a malicious file i
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064118.htmlhttp://secunia.com/advisories/31713http://security.gentoo.org/glsa/glsa-201209-25.xmlhttp://securityreason.com/securityalert/4202http://securitytracker.com/id?1020794http://www.securityfocus.com/archive/1/495869/100/0/threadedhttp://www.securityfocus.com/bid/30937http://www.vmware.com/security/advisories/VMSA-2008-0014.htmlhttp://www.vupen.com/english/advisories/2008/2466https://exchange.xforce.ibmcloud.com/vulnerabilities/44797http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064118.htmlhttp://secunia.com/advisories/31713http://security.gentoo.org/glsa/glsa-201209-25.xmlhttp://securityreason.com/securityalert/4202http://securitytracker.com/id?1020794http://www.securityfocus.com/archive/1/495869/100/0/threadedhttp://www.securityfocus.com/bid/30937http://www.vmware.com/security/advisories/VMSA-2008-0014.htmlhttp://www.vupen.com/english/advisories/2008/2466https://exchange.xforce.ibmcloud.com/vulnerabilities/44797
2008-09-03
Published