The Web Configuration tool in VMware vCenter Orchestrator (vCO) 4.0 before Update 4, 4.1 before Update 2, and 4.2 before Update 1 places the vCenter Server password in an HTML document, which allows remote authenticated administrators to obtain sensitive information by reading this document.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/52525 | vdb entry |
http://secunia.com/advisories/48408 | third party advisory |
http://osvdb.org/80120 | vdb entry |
http://www.securitytracker.com/id?1026816 | vdb entry |
http://www.vmware.com/security/advisories/VMSA-2012-0005.html | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/74091 | vdb entry |