First published: Mon May 09 2011(Updated: )
vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1 allows local users to discover the SOAP session ID via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vCenter | =4.0-update_1 | |
VMware vCenter | =4.1 | |
VMware vCenter | =4.0 | |
VMware vCenter | =4.0-update_2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1788 is classified with a high severity due to the potential for local users to compromise session IDs.
To address CVE-2011-1788, upgrade VMware vCenter to version 4.0 Update 3 or 4.1 Update 1 or later.
CVE-2011-1788 affects VMware vCenter versions 4.0 before Update 3 and 4.1 before Update 1.
Yes, CVE-2011-1788 can allow local users to exploit the vulnerability to obtain SOAP session IDs, leading to unauthorized access.
There are no specific workarounds for CVE-2011-1788; patching is the recommended solution.