VMware vCenter Server Products Multiple Vulnerabilities
Last Update Date:
29 Apr 2013 18:29
Release Date:
29 Apr 2013
4242
Views
RISK: High Risk
TYPE: Operating Systems - VM Ware
Multiple vulnerabilities have been identified in VMware vCenter Server products, which can be exploited by attacker to bypass certain security restrictions, disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.
- The authentication mechanism when using Active Directory (AD) with anonymous LDAP binding does not properly verify login credentials. This can be exploited to bypass authentication and login as an arbitrary user by providing a valid user name and a blank password.
- An error within the Virtual Appliance Management Interface (VAMI) can be exploited to execute existing files as root.
- An error within the Virtual Appliance Management Interface (VAMI) can be exploited to upload malicious files to an arbitrary location.
- The application bundled a vulnerable version of Java.
Impact
- Denial of Service
- Remote Code Execution
- Security Restriction Bypass
- Information Disclosure
System / Technologies affected
- VMware vCenter Server 5.x
- VMware vCenter Server Appliance 5.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 5.1 Update 1.
Vulnerability Identifier
- CVE-2012-1531
- CVE-2012-1532
- CVE-2012-1533
- CVE-2012-2733
- CVE-2012-3143
- CVE-2012-3159
- CVE-2012-3216
- CVE-2012-3546
- CVE-2012-4416
- CVE-2012-4431
- CVE-2012-4534
- CVE-2012-5067
- CVE-2012-5068
- CVE-2012-5069
- CVE-2012-5070
- CVE-2012-5071
- CVE-2012-5072
- CVE-2012-5073
- CVE-2012-5074
- CVE-2012-5075
- CVE-2012-5076
- CVE-2012-5077
- CVE-2012-5078
- CVE-2012-5079
- CVE-2012-5080
- CVE-2012-5081
- CVE-2012-5082
- CVE-2012-5083
- CVE-2012-5084
- CVE-2012-5085
- CVE-2012-5086
- CVE-2012-5087
- CVE-2012-5088
- CVE-2012-5089
- CVE-2012-5885
- CVE-2012-5886
- CVE-2012-5887
- CVE-2013-3079
- CVE-2013-3080
- CVE-2013-3107
Source
Related Link
Share with