PT-2005-4383 · Vmware · Vmware Esx Server

Published

2005-12-31

·

Updated

2018-10-30

·

CVE-2005-3620

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions VMware ESX Server versions 2.0.x through 2.0.1 VMware ESX Server versions 2.1.x through 2.1.2 VMware ESX Server versions 2.x through 2.5.2
Description The management interface records passwords in cleartext in URLs that are stored in world-readable web server log files, allowing local users to gain privileges.
Recommendations For versions 2.0.x through 2.0.1, update to version 2.0.2 patch 1. For versions 2.1.x through 2.1.2, update to version 2.1.3 patch 1. For versions 2.x through 2.5.2, update to version 2.5.3 patch 2.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3620

Affected Products

Vmware Esx Server