CVE-2019-5537
Published: Oct 28, 2019
Modified: Aug 4, 2024
Description
Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d) may allow a malicious actor to intercept sensitive data in transit over FTPS and HTTPS. A malicious actor with man-in-the-middle positioning between vCenter Server Appliance and a backup target may be able to intercept sensitive data in transit during File-Based Backup and Restore operations.
| Vendor | Product | Versions |
|---|---|---|
n/a | VMware vCenter Server Appliance | affected VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d) |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now