First published: Tue Aug 01 2017(Updated: )
VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtained when using the vCenter Server Appliance file-based backup feature.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vCenter | =6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-4923 is classified as a medium severity information disclosure vulnerability.
To fix CVE-2017-4923, you should upgrade to VMware vCenter Server version 6.5 U1 or later.
CVE-2017-4923 may allow an attacker to obtain plaintext credentials through the file-based backup feature in vCenter Server.
CVE-2017-4923 affects VMware vCenter Server 6.5 prior to version 6.5 U1.
There are no official workarounds available for CVE-2017-4923; upgrading is the recommended solution.