CVE-2011-1788
published 2011-05-09CVE-2011-1788: vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1 allows local users to discover the SOAP session ID via unspecified vectors.
PriorityP44low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.37%
28.8th percentile
vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1 allows local users to discover the SOAP session ID via unspecified vectors.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | vcenter | — | — |
| vmware | vcenter | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3r4f-8jgm-m5g9: vCenter Server in VMware vCenter 4
ghsa_unreviewed·2022-05-17
CVE-2011-1788 [LOW] CWE-200 GHSA-3r4f-8jgm-m5g9: vCenter Server in VMware vCenter 4
vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1 allows local users to discover the SOAP session ID via unspecified vectors.
VMware
VMware vCenter Server and vSphere Client security vulnerabilities
vendor_vmware·2011-05-05·CVSS 4.3
CVE-2011-0426 [MEDIUM] VMware vCenter Server and vSphere Client security vulnerabilities
VMSA-2011-0008: VMware vCenter Server and vSphere Client security vulnerabilities
a. vCenter Server Directory Traversal vulnerability A directory traversal vulnerability allows an attacker to remotely retrieve files from vCenter Server without authentication. In order to exploit this vulnerability, the attacker will need to have access to the network on which the vCenter Server host resides. In case vCenter Server is installed on Windows 2008 or Windows 2008 R2, the security vulnerability is not present. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2011-0426 to this issue. VMware Product ============= Product Version ======= Running on ======= Replace with/ Apply Patch ================= VMware Product ============= vCenter Product Version ====
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.vmware.com/pipermail/security-announce/2011/000137.htmlhttp://osvdb.org/72179http://securitytracker.com/id?1025502http://www.securityfocus.com/bid/47742http://www.vmware.com/security/advisories/VMSA-2011-0008.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/67304http://lists.vmware.com/pipermail/security-announce/2011/000137.htmlhttp://osvdb.org/72179http://securitytracker.com/id?1025502http://www.securityfocus.com/bid/47742http://www.vmware.com/security/advisories/VMSA-2011-0008.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/67304
2011-05-09
Published