CVE-2019-5532: High severity vmware vcenter vulnerability
VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability due to the logging of credentials in plain-text for virtual machines deployed through OVF. A malicious user with access to the log files containing vCenter OVF-properties of a virtual machine deployed from an OVF may be able to view the credentials used to deploy the OVF (typically the root account of the virtual machine).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-5532?
CVE-2019-5532 is a vulnerability in VMware vCenter Server that allows for information disclosure due to the logging of credentials in plain-text for virtual machines deployed through OVF.
How severe is CVE-2019-5532?
CVE-2019-5532 is considered a high severity vulnerability with a CVSS score of 7.7.
Which versions of VMware vCenter Server are affected by CVE-2019-5532?
Versions 6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3, and 6.0 prior to 6.0 U3j of VMware vCenter Server are affected by CVE-2019-5532.
How can I fix CVE-2019-5532?
To fix CVE-2019-5532, update your VMware vCenter Server to version 6.7 U3, 6.5 U3, or 6.0 U3j.
Where can I find more information about CVE-2019-5532?
More information about CVE-2019-5532 can be found in the following references: [Link 1](http://packetstormsecurity.com/files/154536/VMware-Security-Advisory-2019-0013.html), [Link 2](https://www.vmware.com/security/advisories/VMSA-2019-0013.html).