First published: Wed Sep 18 2019(Updated: )
VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability due to the logging of credentials in plain-text for virtual machines deployed through OVF. A malicious user with access to the log files containing vCenter OVF-properties of a virtual machine deployed from an OVF may be able to view the credentials used to deploy the OVF (typically the root account of the virtual machine).
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vCenter Server | =6.0 | |
VMware vCenter Server | =6.0-a | |
VMware vCenter Server | =6.0-b | |
VMware vCenter Server | =6.0-u1 | |
VMware vCenter Server | =6.0-u1b | |
VMware vCenter Server | =6.0-u3 | |
VMware vCenter Server | =6.0-update2 | |
VMware vCenter Server | =6.0-update2a | |
VMware vCenter Server | =6.0-update2m | |
VMware vCenter Server | =6.0-update3a | |
VMware vCenter Server | =6.0-update3b | |
VMware vCenter Server | =6.0-update3c | |
VMware vCenter Server | =6.0-update3d | |
VMware vCenter Server | =6.0-update3e | |
VMware vCenter Server | =6.0-update3f | |
VMware vCenter Server | =6.0-update3g | |
VMware vCenter Server | =6.0-update3h | |
VMware vCenter Server | =6.0-update3i | |
VMware vCenter Server | =6.7 | |
VMware vCenter Server | =6.7-a | |
VMware vCenter Server | =6.7-b | |
VMware vCenter Server | =6.7-c | |
VMware vCenter Server | =6.7-d | |
VMware vCenter Server | =6.7-update1 | |
VMware vCenter Server | =6.7-update1b | |
VMware vCenter Server | =6.7-update2 | |
VMware vCenter Server | =6.7-update2a | |
VMware vCenter Server | =6.7-update2c | |
VMware vCenter Server | =6.5 | |
VMware vCenter Server | =6.5-a | |
VMware vCenter Server | =6.5-b | |
VMware vCenter Server | =6.5-c | |
VMware vCenter Server | =6.5-d | |
VMware vCenter Server | =6.5-update1 | |
VMware vCenter Server | =6.5-update1b | |
VMware vCenter Server | =6.5-update1c | |
VMware vCenter Server | =6.5-update1d | |
VMware vCenter Server | =6.5-update1e | |
VMware vCenter Server | =6.5-update1g | |
VMware vCenter Server | =6.5-update2 | |
VMware vCenter Server | =6.5-update2b | |
VMware vCenter Server | =6.5-update2c | |
VMware vCenter Server | =6.5-update2d | |
VMware vCenter Server | =6.5-update2g |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5532 is a vulnerability in VMware vCenter Server that allows for information disclosure due to the logging of credentials in plain-text for virtual machines deployed through OVF.
CVE-2019-5532 is considered a high severity vulnerability with a CVSS score of 7.7.
Versions 6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3, and 6.0 prior to 6.0 U3j of VMware vCenter Server are affected by CVE-2019-5532.
To fix CVE-2019-5532, update your VMware vCenter Server to version 6.7 U3, 6.5 U3, or 6.0 U3j.
More information about CVE-2019-5532 can be found in the following references: [Link 1](http://packetstormsecurity.com/files/154536/VMware-Security-Advisory-2019-0013.html), [Link 2](https://www.vmware.com/security/advisories/VMSA-2019-0013.html).