7.5

CVE-2010-0686

WebAccess in VMware VirtualCenter 2.0.2 and 2.5, VMware Server 2.0, and VMware ESX 3.0.3 and 3.5 allows remote attackers to leverage proxy-server functionality to spoof the origin of requests via unspecified vectors, related to a "URL forwarding vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Virtualcenter Version 2.0.2
VMware ≫ Virtualcenter Version 2.5
VMware ≫ Server Version 2.0.0
VMware ≫ Esx Server Version 3.0.3
VMware ≫ Esx Server Version 3.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.18% 0.8
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://lists.vmware.com/pipermail/security-announce/2010/000086.html
Patch
Vendor Advisory
http://www.securityfocus.com/bid/39037
Patch
http://www.vmware.com/security/advisories/VMSA-2010-0005.html
Patch
Vendor Advisory
http://www.securitytracker.com/id?1023769