VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtained when using the vCenter Server Appliance file-based backup feature.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.vmware.com/security/advisories/VMSA-2017-0013.html | patch vendor advisory |
http://www.securityfocus.com/bid/99997 | vdb entry third party advisory |
http://www.securitytracker.com/id/1039013 | vdb entry third party advisory |