The VMware Consolidated Backup (VCB) command-line utilities in VMware ESX 3.0.1 through 3.0.3 and ESX 3.5 place a password on the command line, which allows local users to obtain sensitive information by listing the process.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://security.gentoo.org/glsa/glsa-201209-25.xml | vendor advisory |
http://www.vmware.com/security/advisories/VMSA-2008-0014.html | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/44797 | vdb entry |
http://secunia.com/advisories/31713 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/30937 | vdb entry |
http://www.securityfocus.com/archive/1/495869/100/0/threaded | mailing list |
http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064118.html | mailing list |
http://securitytracker.com/id?1020794 | vdb entry |
http://securityreason.com/securityalert/4202 | third party advisory |
http://www.vupen.com/english/advisories/2008/2466 | vdb entry |