Path traversal in vCenter Server Appliance - CVE-2012-6324
Published: December 21, 2012 / Updated: August 11, 2020
vCenter Server Appliance
Detailed vulnerability description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in VMware vCenter Server Appliance (vCSA) 5.0 before Update 2 and 5.1 before Patch 1. A remote authenticated attacker can send a specially crafted HTTP request and remote authenticated users to read arbitrary files via unspecified vectors.