// For flags

CVE-2011-4404

VMware - Update Manager Directory Traversal

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Update 2 allows remote attackers to conduct directory traversal attacks and read arbitrary files via unspecified vectors, a related issue to CVE-2009-1523.

La configuración por defecto del servidor HTTP en Jetty en vSphere Update Manager bajo VMware vCenter Update Manager v4.0 antes de la actualización 4 y v4.1 antes de la actualización 2 permite realizar ataques de salto de directorio y leer archivos arbitrarios a atacantes remotos a través de vectores no especificados. Se trata de un problema relacionado con CVE-2009 -1523.

VMware Update Manager versions 4.1 prior to update 2 suffer from a directory traversal vulnerability.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2011-11-07 CVE Reserved
  • 2011-11-18 CVE Published
  • 2011-11-21 First Exploit
  • 2023-03-07 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-16: Configuration
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Vmware
Search vendor "Vmware"
Vcenter Update Manager
Search vendor "Vmware" for product "Vcenter Update Manager"
4.0
Search vendor "Vmware" for product "Vcenter Update Manager" and version "4.0"
-
Affected
Vmware
Search vendor "Vmware"
Vcenter Update Manager
Search vendor "Vmware" for product "Vcenter Update Manager"
4.0
Search vendor "Vmware" for product "Vcenter Update Manager" and version "4.0"
update_1
Affected
Vmware
Search vendor "Vmware"
Vcenter Update Manager
Search vendor "Vmware" for product "Vcenter Update Manager"
4.0
Search vendor "Vmware" for product "Vcenter Update Manager" and version "4.0"
update_2
Affected
Vmware
Search vendor "Vmware"
Vcenter Update Manager
Search vendor "Vmware" for product "Vcenter Update Manager"
4.0
Search vendor "Vmware" for product "Vcenter Update Manager" and version "4.0"
update_3
Affected
Vmware
Search vendor "Vmware"
Vcenter Update Manager
Search vendor "Vmware" for product "Vcenter Update Manager"
4.1
Search vendor "Vmware" for product "Vcenter Update Manager" and version "4.1"
-
Affected
Vmware
Search vendor "Vmware"
Vcenter Update Manager
Search vendor "Vmware" for product "Vcenter Update Manager"
4.1
Search vendor "Vmware" for product "Vcenter Update Manager" and version "4.1"
update_1
Affected