CVE-2011-1788: Infoleak
Published May 9, 2011
·Updated
vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1 allows local users to discover the SOAP session ID via unspecified vectors.
Affected Software
4 affected components
VMware vCenter=4.0-update_1
VMware vCenter=4.1
VMware vCenter=4.0
VMware vCenter=4.0-update_2
Event History
May 9, 2011
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-1788?
CVE-2011-1788 is classified with a high severity due to the potential for local users to compromise session IDs.
2
How do I fix CVE-2011-1788?
To address CVE-2011-1788, upgrade VMware vCenter to version 4.0 Update 3 or 4.1 Update 1 or later.
3
What products are affected by CVE-2011-1788?
CVE-2011-1788 affects VMware vCenter versions 4.0 before Update 3 and 4.1 before Update 1.
4
Can CVE-2011-1788 lead to unauthorized access?
Yes, CVE-2011-1788 can allow local users to exploit the vulnerability to obtain SOAP session IDs, leading to unauthorized access.
5
Is there a workaround for CVE-2011-1788?
There are no specific workarounds for CVE-2011-1788; patching is the recommended solution.