PT-2008-4908 · Vmware · Vmware Virtualcenter
Publicado
2008-08-13
·
Atualizado
2018-10-11
·
CVE-2008-3514
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
VMware VirtualCenter versions 2.0.2 before Update 5
VMware VirtualCenter versions 2.5 before Update 2
Description
The issue allows remote attackers to determine valid user names by exploiting the client-side access control mechanism. This is done by enabling functionality in the GUI and then attempting to assign permissions to other system users.
Recommendations
For versions 2.0.2 before Update 5, update to Update 5 or later.
For versions 2.5 before Update 2, update to Update 2 or later.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Vmware Virtualcenter