Sensitive Information Disclosure in VMware vCenter Server Appliance
CVE-2019-5537
5.9MEDIUM
Key Information:
- Vendor
Vmware
- Vendor
- CVE Published:
- 28 October 2019
What is CVE-2019-5537?
A vulnerability in VMware vCenter Server Appliance exposes sensitive information due to insufficient certificate validation during File-Based Backup and Restore operations. This allows adversaries positioned as a man-in-the-middle to intercept sensitive data transmitted over FTPS and HTTPS, particularly when backing up data to a target. It is essential for users to ensure proper validations and configurations to mitigate risks associated with this vulnerability.
Affected Version(s)
VMware vCenter Server Appliance VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d)