Show filters
121 Total Results
Displaying 71-80 of 121
Sort by:
Attacker Value
Unknown

Cross-Site Scripting Vulnerability while registering vCenter servers

Disclosure Date: April 17, 2019 (last updated October 06, 2023)
IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while registering vCenter servers. A remote attacker can trick an admin user to potentially exploit this vulnerability to execute malicious HTML or JavaScript code in the context of the admin user.
Attacker Value
Unknown

CVE-2018-1223

Disclosure Date: September 17, 2018 (last updated October 06, 2023)
Cloud Foundry Container Runtime (kubo-release), versions prior to 0.14.0, may leak UAA and vCenter credentials to application logs. A malicious user with the ability to read the application logs could use these credentials to escalate privileges.
Attacker Value
Unknown

CVE-2018-5761

Disclosure Date: January 22, 2018 (last updated October 06, 2023)
A man-in-the-middle vulnerability related to vCenter access was found in Rubrik CDM 3.x and 4.x before 4.0.4-p2. This vulnerability might expose Rubrik user credentials configured to access vCenter as Rubrik clusters did not verify TLS certificates presented by vCenter.
Attacker Value
Unknown

CVE-2017-4943

Disclosure Date: December 20, 2017 (last updated October 05, 2023)
VMware vCenter Server Appliance (vCSA) (6.5 before 6.5 U1d) contains a local privilege escalation vulnerability via the 'showlog' plugin. Successful exploitation of this issue could result in a low privileged user gaining root level privileges over the appliance base OS.
Attacker Value
Unknown

CVE-2017-4927

Disclosure Date: November 17, 2017 (last updated October 05, 2023)
VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle specially crafted LDAP network packets which may allow for remote denial of service.
Attacker Value
Unknown

CVE-2017-1378

Disclosure Date: October 05, 2017 (last updated October 05, 2023)
IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed unencrypted login credentials to Vmware vCenter in the application trace output which could be obtained by a local user. IBM X-Force ID: 126875.
Attacker Value
Unknown

CVE-2017-4926

Disclosure Date: September 15, 2017 (last updated October 05, 2023)
VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which will get executed when other VC users access the page.
Attacker Value
Unknown

CVE-2017-4922

Disclosure Date: August 01, 2017 (last updated October 05, 2023)
VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the service startup script using world writable directories as temporary storage for critical information. Successful exploitation of this issue may allow unprivileged host users to access certain critical information when the service gets restarted.
Attacker Value
Unknown

CVE-2017-4921

Disclosure Date: August 01, 2017 (last updated October 05, 2023)
VMware vCenter Server (6.5 prior to 6.5 U1) contains an insecure library loading issue that occurs due to the use of LD_LIBRARY_PATH variable in an unsafe manner. Successful exploitation of this issue may allow unprivileged host users to load a shared library that may lead to privilege escalation.
Attacker Value
Unknown

CVE-2017-4923

Disclosure Date: August 01, 2017 (last updated October 05, 2023)
VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtained when using the vCenter Server Appliance file-based backup feature.