CVE-2008-2101: Infoleak
The VMware Consolidated Backup (VCB) command-line utilities in VMware ESX 3.0.1 through 3.0.3 and ESX 3.5 place a password on the command line, which allows local users to obtain sensitive information by listing the process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2101?
CVE-2008-2101 is categorized as a high-severity vulnerability due to its potential to expose sensitive information through process listing.
How do I fix CVE-2008-2101?
To fix CVE-2008-2101, upgrade your VMware ESX to versions 3.5 Update 1 or later, which address the password exposure issue.
Which versions of VMware are affected by CVE-2008-2101?
CVE-2008-2101 affects VMware ESX versions 3.0.1 to 3.0.3 and 3.5.
What type of vulnerability is CVE-2008-2101 classified as?
CVE-2008-2101 is classified as a local security vulnerability that reveals sensitive information.
Can local users exploit CVE-2008-2101?
Yes, local users can exploit CVE-2008-2101 to obtain sensitive information by listing the process with passwords on the command line.