vendor:
VMware Update Manager
by:
Alexey Sintsov
7.8
CVSS
(CVSS2)
Directory Traversal File Read
22
CWE
Product Name: VMware Update Manager
Affected Version From: vCenter Update Manager 4.1 prior to Update 2
Affected Version To: vCenter Update Manager 4.0 prior to Update 4
Patch Exists: YES
Related CWE: CVE-2011-4404
CPE: a:vmware:vcenter_update_manager
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 2003 / vCenter Update Manager 4.1 U1
2011
VMware Update Manager Directory Traversal
Directory Traversal vulnerability was found in Jetty web server that is used by VMware Update manager. With this vulnerability, an non-authenticated attacker can read any file on the server (with rights of the process).
Mitigation:
Fixed in Update Manager 5.0 Windows not affected Fixed in Update Manager 4.1 Windows Update 2 Fixed in Update Manager 4.0 Windows Update 4