« Volver al listado

CVE-2011-1788

Estado: ModificadaBaja (2.1)—

vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1 allows local users to discover the SOAP session ID via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-1788",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-05-09T22:55:03.177",
  "references": [
    {
      "url": "http://lists.vmware.com/pipermail/security-announce/2011/000137.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/72179",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1025502",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/47742",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vmware.com/security/advisories/VMSA-2011-0008.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/67304",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.vmware.com/pipermail/security-announce/2011/000137.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/72179",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1025502",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/47742",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vmware.com/security/advisories/VMSA-2011-0008.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/67304",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "vCenter Server in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1 allows local users to discover the SOAP session ID via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "vCenter Server en VMware vCenter v4.0 anterior a la actualización 3 y v4.1 anterior a la actualización 1 permite a los usuarios locales descubrir el ID de las sesiones SOAP mediante vectores no especificados."
    }
  ],
  "lastModified": "2026-06-16T23:30:07.617",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:vcenter:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "60B31894-78E7-41A6-857C-D7A0C1C52838"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter:4.0:update_1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8087D4A0-D416-4746-8EE6-9833C20B7BE3"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter:4.0:update_2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "613AC011-EED1-49C2-9A6B-4C3BF0EBE8EE"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter:4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "15C55340-9A59-4FD6-A6BD-1F68E8FE9692"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}