CVE Database
/

CVE-2008-3514

Back to search

CVE-2008-3514

Published: Aug 13, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

VMware VirtualCenter 2.5 before Update 2 and 2.0.2 before Update 5 relies on client-side "enabled/disabled functionality" for access control, which allows remote attackers to determine valid user names by enabling functionality in the GUI and then making an "attempt to assign permissions to other system users."

VendorProductVersions

n/a

n/a

affected
n/a

References

31468
third-party-advisory
x_refsource_SECUNIA
ADV-2008-2363
vdb-entry
x_refsource_VUPEN
4150
third-party-advisory
x_refsource_SREASON
1020693
vdb-entry
x_refsource_SECTRACK
30664
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now