← Vulnerability feed

Vulnerability record · CVE-2011-4404 · published 19 November 2011

CVE-2011-4404: VMware vCenter Update Manager Jetty default config directory traversal

Vmware · Vcenter Update Manager

The HTTP server bundled with Jetty in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Update 2 ships with a default configuration that permits directory traversal. A remote attacker can read arbitrary files from the host, and the flaw is a related issue to CVE-2009-1523. Because the vulnerable component is the management server itself, exposed file contents can include sensitive configuration or credential material.

5.0 CVSS 2.0 Medium EPSS 60% · top 0.9% CWE-16 · CWE-16
5.0CVSS 2.0 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Update 2 allows remote attackers to conduct directory traversal attacks and read arbitrary files via unspecified vectors, a related issue to CVE-2009-1523.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote arbitrary file read on a management server is serious, though the CVSS 2.0 score is only 5.0 and no active exploitation is documented.

What it is

The HTTP server bundled with Jetty in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Update 2 ships with a default configuration that permits directory traversal. A remote attacker can read arbitrary files from the host, and the flaw is a related issue to CVE-2009-1523. Because the vulnerable component is the management server itself, exposed file contents can include sensitive configuration or credential material.

Impact

An unauthenticated remote attacker gains read access to arbitrary files on the Update Manager host, which can expose credentials, configuration and other sensitive data. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reachable over the network via the Jetty HTTP server (AV:N, AC:L, Au:N), so no authentication and no user interaction are required. The description does not specify the exact request vectors, only that they are unspecified.

Exploitation

Not listed in CISA KEV and no reference is tagged as exploit code, so no confirmed in-the-wild exploitation is documented. EPSS is high (0.597, 99th percentile), indicating elevated predicted likelihood, but that is a model estimate, not evidence of active exploitation.

What to do

  • Apply the VMware patch per VMSA-2011-0014, upgrading vCenter Update Manager 4.0 to Update 4 or later and 4.1 to Update 2 or later.
  • If patching is delayed, restrict network access to the Update Manager HTTP/Jetty port to trusted management networks only.
  • Review and harden the Jetty default configuration so directory traversal paths are rejected, following the referenced Jetty ResourceHandler and DefaultServlet behavior.
  • Rotate any credentials or secrets that may have been stored in files readable through the traversal.
  • Confirm no unsupported or end-of-life vCenter Update Manager 4.x instances remain exposed.

Detection

  • Search Jetty/Update Manager access logs for requests containing traversal sequences such as ../ or encoded variants (..%2f, %2e%2e) targeting file paths.
  • Alert on HTTP requests to the Update Manager Jetty port from hosts outside the expected management network.
  • Monitor for reads of sensitive files (configuration, keystores, credential stores) on Update Manager hosts via file access auditing.
  • Inventory vCenter Update Manager versions and flag any still running 4.0 before Update 4 or 4.1 before Update 2.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-4404 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2011-4404), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.