References https://www.sentinelone.com/vulnerability-database/cve-2020-3952/ https://www.akamai.com/blog/security/pwning-vmware-vcenter-cve-2020-3952 https://www.hhs.gov/sites/default/files/vmware-directory-service-critical-vulnerability_0.pdf https://www.rapid7.com/db/vulnerabilities/vmsa-2020-0006-cve-2020-3952-vcenter/ https://www.tenable.com/blog/cve-2020-3952-sensitive-information-disclosure-in-vmware-vcenter-server-vmsa-2020-0006 https://horizon3.ai/attack-research/attack-blogs/compromising-vcenter-via-saml-certificates/ https://www.geekby.site/2022/05/vcenter%E6%BC%8F%E6%B4%9E%E5%88%A9%E7%94%A8/ https://www.hkcert.org/tc/security-bulletin/vmware-vcenter-server-products-multiple-vulnerabilities https://www.asiainfo-sec.com/about/news/detail-6243.html https://securityaffairs.com/101388/security/cve-2020-3952-vmware-vcenter-server.html https://www.helpnetsecurity.com/2020/04/14/cve-2020-3952/
Related VulnerabilitiesCuteHttpFileServer/chfs存在未授权任意文件上传PoCCVE-2026-26265: Discourse - Private User Field Disclosure via Directory Items IDOR畅捷通 T+ POSSyncService.asmx 接口SQL注入漏洞北京亿赛通科技发展有限责任公司电子文档安全管理系统CDGServer3-client存在前台sql漏洞PoCCVE-2026-42596: Gotenberg < 8.31.0 - Server-Side Request ForgeryWordPress Directory Kit 插件敏感信息泄露漏洞(CVE-2025-13920)PoCCVE-2026-45695: Kopia Server 0.23.0 - Remote Code ExecutionPoCCVE-2017-7504: JBossMQ HTTP Invocation Layer (HTTPServerILServlet) - Unauthenticated Java DeserializationPoCCVE-2026-23536: Feast Feature Server <=0.58.0 - Arbitrary File ReadPoCCVE-2026-76904: GeoServer jsonArrayContains CQL Filter - SQL Injection網韻資訊|NewSiteServer (NSS) 新式校園網站系統 - Missing Authentication網韻資訊|NewSiteServer (NSS)新式校園網站系統 - Arbitrary File UploadPoCCVE-2026-35037: Ech0 < 4.2.8 - Server-Side Request Forgery