CVE-2013-5971: VMware vCenter Server

Medium severity, CVSS 6.8. EPSS: 2% chance of exploitation in the next 30 days.

Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web sessions and gain privileges via unspecified vectors.

Affected products

  • VMware vCenter Server: up to and including 5.0; version 4.0.0.10021 only; version 4.0.0.12305 only; version 4.1 only; version 4.1.0.12319 only; version 4.1.0.14766 only; …

Published 2013-10-21. Last modified 2026-06-16.