vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1 allows local users to discover the SOAP session ID via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/47742 | vdb entry |
http://lists.vmware.com/pipermail/security-announce/2011/000137.html | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/67304 | vdb entry |
http://osvdb.org/72179 | vdb entry |
http://securitytracker.com/id?1025502 | vdb entry |
http://www.vmware.com/security/advisories/VMSA-2011-0008.html | vendor advisory |