First published: Mon Oct 21 2013(Updated: )
Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web sessions and gain privileges via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vCenter | <=5.0 | |
VMware vCenter | =4.0.0.10021 | |
VMware vCenter | =4.0.0.12305 | |
VMware vCenter | =4.1 | |
VMware vCenter | =4.1.0.12319 | |
VMware vCenter | =4.1.0.14766 | |
VMware vCenter | =4.1.0.17435 | |
VMware vCenter | =5.0 | |
VMware vCenter | =5.0-update_1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5971 is rated as a medium-severity vulnerability due to its impact on session hijacking.
To fix CVE-2013-5971, it is recommended to apply the latest updates released by VMware for vCenter Server.
CVE-2013-5971 affects multiple versions including vCenter Server 4.0, 4.1, and 5.0 before Update 3.
CVE-2013-5971 is a session fixation vulnerability that allows attackers to hijack web sessions.
Yes, CVE-2013-5971 can be exploited by remote attackers, making it crucial to secure affected systems.