VMware vCenter Server Appliance (vCSA) Unspecified Directory Traversal Vulnerability
BID:57021
Info
VMware vCenter Server Appliance (vCSA) Unspecified Directory Traversal Vulnerability
| Bugtraq ID: | 57021 |
| Class: | Unknown |
| CVE: |
CVE-2012-6324 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 20 2012 12:00AM |
| Updated: | Dec 20 2012 12:00AM |
| Credit: | Alexander Minozhenko |
| Vulnerable: |
VMWare vCenter Server Appliance 5.1 VMWare vCenter Server Appliance 5.0 |
| Not Vulnerable: |
VMWare vCenter Server Appliance 5.1 Patch 1 VMWare vCenter Server Appliance 5.0 Update 2 |
Discussion
VMware vCenter Server Appliance (vCSA) Unspecified Directory Traversal Vulnerability
VMware vCenter Server Appliance (vCSA) is prone to an unspecified directory-traversal vulnerability.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to retrieve arbitrary files in the context of the application.
Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks.
VMware vCenter Server Appliance (vCSA) is prone to an unspecified directory-traversal vulnerability.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to retrieve arbitrary files in the context of the application.
Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Exploit / POC
VMware vCenter Server Appliance (vCSA) Unspecified Directory Traversal Vulnerability
Attackers can exploit this issue with a web browser or readily available tools.
Attackers can exploit this issue with a web browser or readily available tools.
Solution / Fix
VMware vCenter Server Appliance (vCSA) Unspecified Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
VMware vCenter Server Appliance (vCSA) Unspecified Directory Traversal Vulnerability
References:
References:
- VMware Homepage (VMware)
- VMSA-2012-0018 (VMware)