Inclusion of Sensitive Information in Log Files in vCenter Server - CVE-2022-31697
Published: December 9, 2022
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to software stores credentials in plain text into log files. A local user with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext passwords used during that operation.
Affected software
IBM Cloud Pak System
PowerFlex Appliance
PowerFlex rack
How to mitigate CVE-2022-31697
IBM Cloud Pak System - update to 2.3.3.6
PowerFlex Appliance - update to IC 38.363.02
PowerFlex rack - update to 3.6.3.2