CVE Database
/

CVE-2019-5537

Back to search

CVE-2019-5537

Published: Oct 28, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d) may allow a malicious actor to intercept sensitive data in transit over FTPS and HTTPS. A malicious actor with man-in-the-middle positioning between vCenter Server Appliance and a backup target may be able to intercept sensitive data in transit during File-Based Backup and Restore operations.

VendorProductVersions

n/a

VMware vCenter Server Appliance

affected
VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now