PT-2005-4381 · Vmware · Vmware Esx Server
Published
2005-12-31
·
Updated
2018-10-30
·
CVE-2005-3618
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VMware ESX Server versions 2.0.x through 2.0.1
VMware ESX Server versions 2.1.x through 2.1.2
VMware ESX Server versions 2.x through 2.5.2
Description
A cross-site request forgery (CSRF) issue exists in the management interface, allowing remote attackers to perform unauthorized actions as the administrator via URLs. This can be demonstrated using the setUsr operation to change a password.
Recommendations
For versions 2.0.x through 2.0.1, update to version 2.0.2 patch 1.
For versions 2.1.x through 2.1.2, update to version 2.1.3 patch 1.
For versions 2.x through 2.5.2, update to version 2.5.3 patch 2.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vmware Esx Server