CVE-2010-0686: Input Validation
WebAccess in VMware VirtualCenter 2.0.2 and 2.5, VMware Server 2.0, and VMware ESX 3.0.3 and 3.5 allows remote attackers to leverage proxy-server functionality to spoof the origin of requests via unspecified vectors, related to a "URL forwarding vulnerability."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0686?
CVE-2010-0686 has a high severity rating due to its potential for exploiting proxy-server functionality for request spoofing.
How do I fix CVE-2010-0686?
To fix CVE-2010-0686, update VMware VirtualCenter, VMware Server, or VMware ESX to the latest version provided by VMware.
What impact does CVE-2010-0686 have on affected systems?
CVE-2010-0686 allows remote attackers to spoof the origin of requests, which can lead to unauthorized access or manipulation of data.
Which versions are affected by CVE-2010-0686?
CVE-2010-0686 affects VMware VirtualCenter versions 2.0.2 and 2.5, VMware Server 2.0.0, and VMware ESX versions 3.0.3 and 3.5.
Is there a workaround for CVE-2010-0686?
There are no documented workarounds for CVE-2010-0686, so it is advised to apply patches provided by VMware.