Information disclosure in vCenter Server - CVE-2024-22275
Published: September 4, 2024
Vulnerability identifier: #VU96788
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-22275
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to read files on the system.
The vulnerability exists due to improper access restrictions. A remote user with administrative privileges on the vCenter appliance shell can partially read arbitrary files containing sensitive data.
Affected software
vCenter Server
IBM Cloud Pak System
PowerProtect DP Series Appliance (IDPA)
IBM Cloud Pak System
PowerProtect DP Series Appliance (IDPA)
How to mitigate CVE-2024-22275
Install updates from vendor's website.
vCenter Server - addressed in versions 7.0 U3q, 8.0 U2b
IBM Cloud Pak System - update to 2.3.4.1
PowerProtect DP Series Appliance (IDPA) - update to 2.7.7
IBM Cloud Pak System - update to 2.3.4.1
PowerProtect DP Series Appliance (IDPA) - update to 2.7.7