CVE-2012-1513
published 2012-03-16CVE-2012-1513: The Web Configuration tool in VMware vCenter Orchestrator (vCO) 4.0 before Update 4, 4.1 before Update 2, and 4.2 before Update 1 places the vCenter Server…
PriorityP415medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
1.21%
64.8th percentile
The Web Configuration tool in VMware vCenter Orchestrator (vCO) 4.0 before Update 4, 4.1 before Update 2, and 4.2 before Update 1 places the vCenter Server password in an HTML document, which allows remote authenticated administrators to obtain sensitive information by reading this document.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esxi | — | — |
| vmware | vcenter_orchestrator | — | — |
| vmware | vcenter_orchestrator | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pv9q-9grm-74mr: The Web Configuration tool in VMware vCenter Orchestrator (vCO) 4
ghsa_unreviewed·2022-05-14
CVE-2012-1513 [MEDIUM] CWE-200 GHSA-pv9q-9grm-74mr: The Web Configuration tool in VMware vCenter Orchestrator (vCO) 4
The Web Configuration tool in VMware vCenter Orchestrator (vCO) 4.0 before Update 4, 4.1 before Update 2, and 4.2 before Update 1 places the vCenter Server password in an HTML document, which allows remote authenticated administrators to obtain sensitive information by reading this document.
VMware
VMware vCenter Server, Orchestrator, Update Manager, vShield, vSphere Client, Workstation, Player, ESXi and ESX address several security issues
vendor_vmware·2012-03-15·CVSS 7.2
CVE-2010-0405 [HIGH] VMware vCenter Server, Orchestrator, Update Manager, vShield, vSphere Client, Workstation, Player, ESXi and ESX address several security issues
VMSA-2012-0005: VMware vCenter Server, Orchestrator, Update Manager, vShield, vSphere Client, Workstation, Player, ESXi and ESX address several security issues
a. VMware Tools Display Driver Privilege Escalation The VMware XPDM and WDDM display drivers contain buffer overflow vulnerabilities and the XPDM display driver does not properly check for NULL pointers. Exploitation of these issues may lead to local privilege escalation on Windows-based Guest Operating Systems. VMware would like to thank Tarjei Mandt for reporting theses issues to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CVE-2012-1509 (XPDM buffer overrun), CVE-2012-1510 (WDDM buffer overrun) and CVE-2012-1508 (XPDM null pointer dereference) to these issues. Note: CVE-2012-1509 do
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/80120http://secunia.com/advisories/48408http://www.securityfocus.com/bid/52525http://www.securitytracker.com/id?1026816http://www.vmware.com/security/advisories/VMSA-2012-0005.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/74091http://osvdb.org/80120http://secunia.com/advisories/48408http://www.securityfocus.com/bid/52525http://www.securitytracker.com/id?1026816http://www.vmware.com/security/advisories/VMSA-2012-0005.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/74091
2012-03-16
Published