CVE-2009-3731: XSS
Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156; VMware Server 2.0.2; VMware ESX 4.0; VMware Lab Manager 2.x; VMware vCenter Lab Manager 3.x and 4.x before 4.0.1; VMware Stage Manager 1.x before 4.0.1; WebWorks Publisher 6.x through 8.x; WebWorks Publisher 2003; and WebWorks ePublisher 9.0.x through 9.3, 2008.1 through 2008.4, and 2009.x before 2009.3 allow remote attackers to inject arbitrary web script or HTML via (1) wwhelpentry.html, reachable through index.html and wwhsec.htm, (2) wwhelp/wwhimpl/api.htm, (3) wwhelp/wwhimpl/common/html/frameset.htm, (4) wwhelp/wwhimpl/common/scripts/switch.js, or (5) the window.opener component in wwhelp/wwhimpl/common/html/bookmark.htm, related to (a) unspecified parameters and (b) messages used in topic links for the bookmarking functionality.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3731?
CVE-2009-3731 has a medium severity rating, making it significant but not critical.
How do I fix CVE-2009-3731?
To fix CVE-2009-3731, update affected VMware products to the latest versions as specified in the security advisory.
Which VMware products are affected by CVE-2009-3731?
CVE-2009-3731 affects multiple versions of VMware vCenter, VMware Server, VMware ESX, and WebWorks Help among others.
What types of vulnerabilities does CVE-2009-3731 include?
CVE-2009-3731 includes multiple cross-site scripting (XSS) vulnerabilities.
Can I mitigate CVE-2009-3731 without patching?
While patching is the best solution, implementing proper web application firewalls and input validation can help mitigate CVE-2009-3731.