HIGH · 7.5

CVE-2010-0686

WebAccess in VMware VirtualCenter 2.0.2 and 2.5, VMware Server 2.0, and VMware ESX 3.0.3 and 3.5 allows remote attackers to leverage proxy-server functionality to spoof the origin of requests via unsp...

Vulnerability Description

WebAccess in VMware VirtualCenter 2.0.2 and 2.5, VMware Server 2.0, and VMware ESX 3.0.3 and 3.5 allows remote attackers to leverage proxy-server functionality to spoof the origin of requests via unspecified vectors, related to a "URL forwarding vulnerability."

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
VmwareVirtualcenter2.0.2
VmwareServer2.0.0
VmwareEsx Server3.0.3

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-0686?

CVE-2010-0686 is a vulnerability with a CVSS score of 7.5 (HIGH). WebAccess in VMware VirtualCenter 2.0.2 and 2.5, VMware Server 2.0, and VMware ESX 3.0.3 and 3.5 allows remote attackers to leverage proxy-server functionality to spoof the origin of requests via unsp...

How severe is CVE-2010-0686?

CVE-2010-0686 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-0686?

Check the references section above for vendor advisories and patch information. Affected products include: Vmware Virtualcenter, Vmware Server, Vmware Esx Server.