CVE-2011-4404
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 60%
from disclosure to weapon2 days
Published on NVDNov 19
1st PoC+2d
metasploit+2d
exploitation probability
60%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Update 2 allows remote attackers to conduct directory traversal attacks and read arbitrary files via unspecified vectors, a related issue to CVE-2009-1523.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/18138unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.