VMware vCenter Server SOAP Session ID Information Disclosure Vulnerability
BID:47742
Info
VMware vCenter Server SOAP Session ID Information Disclosure Vulnerability
| Bugtraq ID: | 47742 |
| Class: | Design Error |
| CVE: |
CVE-2011-1788 |
| Remote: | No |
| Local: | Yes |
| Published: | May 05 2011 12:00AM |
| Updated: | May 05 2011 12:00AM |
| Credit: | Claudio Criscione |
| Vulnerable: |
VMWare vCenter 4.1 VMWare vCenter 4.0 |
| Not Vulnerable: |
VMWare vCenter 4.1 Update 1 VMWare vCenter 4.0 Update 3 |
Discussion
VMware vCenter Server SOAP Session ID Information Disclosure Vulnerability
VMware vCenter server is prone to an information-disclosure vulnerability.
A local attacker can exploit this issue to gain elevated privileges.
NOTE: This issue was previously discussed in BID 47735 (VMware vCenter Server and vSphere Client Multiple Security Vulnerabilities) but has been given its own record to better document it.
VMware vCenter server is prone to an information-disclosure vulnerability.
A local attacker can exploit this issue to gain elevated privileges.
NOTE: This issue was previously discussed in BID 47735 (VMware vCenter Server and vSphere Client Multiple Security Vulnerabilities) but has been given its own record to better document it.
Exploit / POC
VMware vCenter Server SOAP Session ID Information Disclosure Vulnerability
An attacker requires local interactive access to the affected application to exploit this issue.
An attacker requires local interactive access to the affected application to exploit this issue.
Solution / Fix
VMware vCenter Server SOAP Session ID Information Disclosure Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
VMware vCenter Server SOAP Session ID Information Disclosure Vulnerability
References:
References: