Sensitive Information Disclosure in VMware vCenter Server Appliance
CVE-2019-5537
Key Information:
- Vendor
Vmware
- Vendor
- CVE Published:
- 28 October 2019
What is CVE-2019-5537?
A vulnerability in VMware vCenter Server Appliance exposes sensitive information due to insufficient certificate validation during File-Based Backup and Restore operations. This allows adversaries positioned as a man-in-the-middle to intercept sensitive data transmitted over FTPS and HTTPS, particularly when backing up data to a target. It is essential for users to ensure proper validations and configurations to mitigate risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
VMware vCenter Server Appliance VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d)
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved