Skip to main content

VMware vCenter Server Products Multiple Vulnerabilities

Last Update Date: 29 Apr 2013 18:29 Release Date: 29 Apr 2013 3699 Views

RISK: High Risk

TYPE: Operating Systems - VM Ware

TYPE: VM Ware

Multiple vulnerabilities have been identified in VMware vCenter Server products, which can be exploited by attacker to bypass certain security restrictions, disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.

  1. The authentication mechanism when using Active Directory (AD) with anonymous LDAP binding does not properly verify login credentials. This can be exploited to bypass authentication and login as an arbitrary user by providing a valid user name and a blank password.
  2. An error within the Virtual Appliance Management Interface (VAMI) can be exploited to execute existing files as root. 
  3. An error within the Virtual Appliance Management Interface (VAMI) can be exploited to upload malicious files to an arbitrary location.
  4. The application bundled a vulnerable version of Java.