CVE-2008-3514
Summary
| CVE | CVE-2008-3514 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-08-13 12:42:00 UTC |
| Updated | 2018-10-11 20:48:00 UTC |
| Description | VMware VirtualCenter 2.5 before Update 2 and 2.0.2 before Update 5 relies on client-side "enabled/disabled functionality" for access control, which allows remote attackers to determine valid user names by enabling functionality in the GUI and then making an "attempt to assign permissions to other system users." |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vmware | Virtualcenter | 2.0.2 | All | All | All |
| Application | Vmware | Virtualcenter | 2.0.2 | update_2 | All | All |
| Application | Vmware | Virtualcenter | 2.0.2 | update_3 | All | All |
| Application | Vmware | Virtualcenter | 2.5 | All | All | All |
| Application | Vmware | Virtualcenter | 2.5 | update_1 | All | All |
| Application | Vmware | Virtualcenter | 2.0.2 | All | All | All |
| Application | Vmware | Virtualcenter | 2.0.2 | update_2 | All | All |
| Application | Vmware | Virtualcenter | 2.0.2 | update_3 | All | All |
| Application | Vmware | Virtualcenter | 2.5 | All | All | All |
| Application | Vmware | Virtualcenter | 2.5 | update_1 | All | All |
| Application | Vmware | Virtualcenter | All | update_4 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| VMSA-2008-0012 - VMware | CONFIRM | www.vmware.com | Patch, Vendor Advisory |
| Page not found | Insomnia Security | MISC | www.insomniasec.com | |
| VMware VirtualCenter 2.0.2 Update 5 Release Notes | CONFIRM | www.vmware.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| VMware VirtualCenter User Account Information Disclosure Vulnerability | BID | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| VMware VirtualCenter User Account Disclosure - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | Vendor Advisory |
| VMware VirtualCenter Discloses Usernames to Remote Users - SecurityTracker | SECTRACK | www.securitytracker.com | |
| SecurityReason - VirtualCenter addresses User Account Disclosure Vulnerability | SREASON | securityreason.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.