#VU7641 Information disclosure in vCenter Server - CVE-2017-4923
Published: August 1, 2017
vCenter Server
VMware, Inc
Description
The vulnerability exists due to improper security restrictions that are set on the vCenter Server Appliance file-based backup feature. A remote attacker can use the file-based backup feature to access important data, such as plaintext credentials, that may be used to conduct further attack.
Successful exploitation of the vulnerability results in information disclosure.