CVE-2013-5971

VMware vCenter Server < 5.0 Update 3 - Session Fixation

Title source: llm
STIX 2.1

Description

Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web sessions and gain privileges via unspecified vectors.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/88134
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/98718
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/63218

Scores

EPSS 0.0050
EPSS Percentile 66.4%

Details

CWE
CWE-264
Status published
Products (8)
vmware/vcenter_server 4.0.0.10021
vmware/vcenter_server 4.0.0.12305
vmware/vcenter_server 4.1
vmware/vcenter_server 4.1.0.12319
vmware/vcenter_server 4.1.0.14766
vmware/vcenter_server 4.1.0.17435
vmware/vcenter_server 5.0 (2 CPE variants)
vmware/vcenter_server < 5.0
Published Oct 21, 2013
Tracked Since Feb 18, 2026