Show filters
61 Total Results
Displaying 21-30 of 61
Sort by:
Attacker Value
Unknown

CVE-2019-5534

Disclosure Date: September 18, 2019 (last updated November 27, 2024)
VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability where Virtual Machines deployed from an OVF could expose login information via the virtual machine's vAppConfig properties. A malicious actor with access to query the vAppConfig properties of a virtual machine deployed from an OVF may be able to view the credentials used to deploy the OVF (typically the root account of the virtual machine).
Attacker Value
Unknown

CVE-2019-5532

Disclosure Date: September 18, 2019 (last updated November 27, 2024)
VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability due to the logging of credentials in plain-text for virtual machines deployed through OVF. A malicious user with access to the log files containing vCenter OVF-properties of a virtual machine deployed from an OVF may be able to view the credentials used to deploy the OVF (typically the root account of the virtual machine).
Attacker Value
Unknown

CVE-2017-4943

Disclosure Date: December 20, 2017 (last updated November 26, 2024)
VMware vCenter Server Appliance (vCSA) (6.5 before 6.5 U1d) contains a local privilege escalation vulnerability via the 'showlog' plugin. Successful exploitation of this issue could result in a low privileged user gaining root level privileges over the appliance base OS.
0
Attacker Value
Unknown

CVE-2017-4927

Disclosure Date: November 17, 2017 (last updated November 26, 2024)
VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle specially crafted LDAP network packets which may allow for remote denial of service.
0
Attacker Value
Unknown

CVE-2017-4926

Disclosure Date: September 15, 2017 (last updated November 26, 2024)
VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which will get executed when other VC users access the page.
0
Attacker Value
Unknown

CVE-2017-4922

Disclosure Date: August 01, 2017 (last updated November 26, 2024)
VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the service startup script using world writable directories as temporary storage for critical information. Successful exploitation of this issue may allow unprivileged host users to access certain critical information when the service gets restarted.
0
Attacker Value
Unknown

CVE-2017-4921

Disclosure Date: August 01, 2017 (last updated November 26, 2024)
VMware vCenter Server (6.5 prior to 6.5 U1) contains an insecure library loading issue that occurs due to the use of LD_LIBRARY_PATH variable in an unsafe manner. Successful exploitation of this issue may allow unprivileged host users to load a shared library that may lead to privilege escalation.
0
Attacker Value
Unknown

CVE-2017-4923

Disclosure Date: August 01, 2017 (last updated November 26, 2024)
VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtained when using the vCenter Server Appliance file-based backup feature.
0
Attacker Value
Unknown

CVE-2017-4919

Disclosure Date: July 28, 2017 (last updated November 26, 2024)
VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to access Guest Operating Systems without the need to authenticate.
0
Attacker Value
Unknown

CVE-2017-4917

Disclosure Date: June 07, 2017 (last updated November 26, 2024)
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained.
0