CVE-2009-3733
Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5 allows remote attackers to read arbitrary files via unspecified vectors.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 83.4%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5 allows remote attackers to read arbitrary files via unspecified vectors.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 83.38% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- vmware/esx · vmware/esxi · vmware/server
- Source
- cve@mitre.org
References
- http://lists.vmware.com/pipermail/security-announce/2009/000069.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/37186Broken Link
- http://security.gentoo.org/glsa/glsa-201209-25.xmlThird Party Advisory
- http://securitytracker.com/id?1023088Third Party Advisory, VDB Entry
- http://securitytracker.com/id?1023089Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/507523/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/36842Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2009-0015.htmlPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/3062Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7822Third Party Advisory
- http://lists.vmware.com/pipermail/security-announce/2009/000069.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/37186Broken Link
- http://security.gentoo.org/glsa/glsa-201209-25.xmlThird Party Advisory
- http://securitytracker.com/id?1023088Third Party Advisory, VDB Entry
- http://securitytracker.com/id?1023089Third Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/507523/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/36842Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2009-0015.htmlPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/3062Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7822Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.