CVE-2008-3514
Summary
| CVE | CVE-2008-3514 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-08-13 12:42:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | VMware VirtualCenter 2.5 before Update 2 and 2.0.2 before Update 5 relies on client-side "enabled/disabled functionality" for access control, which allows remote attackers to determine valid user names by enabling functionality in the GUI and then making an "attempt to assign permissions to other system users." |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vmware | Virtualcenter | 2.0.2 | All | All | All |
| Application | Vmware | Virtualcenter | 2.0.2 | update_2 | All | All |
| Application | Vmware | Virtualcenter | 2.0.2 | update_3 | All | All |
| Application | Vmware | Virtualcenter | 2.5 | All | All | All |
| Application | Vmware | Virtualcenter | 2.5 | update_1 | All | All |
| Application | Vmware | Virtualcenter | All | update_4 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VMware VirtualCenter User Account Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityReason - VirtualCenter addresses User Account Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| VMware VirtualCenter 2.0.2 Update 5 Release Notes | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | |
| VMware VirtualCenter Discloses Usernames to Remote Users - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| VMware VirtualCenter User Account Disclosure - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Page not found | Insomnia Security | af854a3a-2127-422b-91ae-364da2661108 | www.insomniasec.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| VMSA-2008-0012 - VMware | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.