First published: Wed Feb 16 2011(Updated: )
The vCenter Tomcat Management Application in VMware vCenter Server 4.1 before Update 1 stores log-on credentials in a configuration file, which allows local users to gain privileges by reading this file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vCenter | =4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2928 has a medium severity level due to the exposure of stored credentials.
To fix CVE-2010-2928, update VMware vCenter Server to at least version 4.1 Update 1.
CVE-2010-2928 affects VMware vCenter Server version 4.1 prior to Update 1.
Yes, local users can exploit CVE-2010-2928 by accessing sensitive log-on credentials stored in a configuration file.
Yes, unpatched systems remain vulnerable to CVE-2010-2928, allowing unauthorized privilege escalation.