PT-2011-4946 · Vmware+1 · Vcenter Update Manager+1

Published

2011-11-19

·

Updated

2011-12-13

·

CVE-2011-4404

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions vCenter Update Manager versions 4.0 before Update 4 vCenter Update Manager versions 4.1 before Update 2
Description The default configuration of the HTTP server in Jetty in vSphere Update Manager allows remote attackers to conduct directory traversal attacks and read arbitrary files via unspecified vectors.
Recommendations For vCenter Update Manager version 4.0, update to Update 4 or later. For vCenter Update Manager version 4.1, update to Update 2 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-4404

Affected Products

Jetty
Vcenter Update Manager