PT-2017-16205 · Vmware · Vmware Vcenter Server+1

Published

2017-08-01

·

Updated

2017-08-03

·

CVE-2017-4922

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions VMware vCenter Server versions 6.5 prior to 6.5 U1
Description The issue is related to an information disclosure problem. It occurs because the service startup script uses world-writable directories as temporary storage for critical information. This could allow unprivileged host users to access certain critical information when the service gets restarted.
Recommendations For versions 6.5 prior to 6.5 U1, update to version 6.5 U1 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-4922

Affected Products

Vmware Vcenter
Vmware Vcenter Server