Information disclosure in vCenter Server - CVE-2024-22275

 

Information disclosure in vCenter Server - CVE-2024-22275

Published: September 4, 2024


Vulnerability identifier: #VU96788
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-22275
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to read files on the system.

The vulnerability exists due to improper access restrictions. A remote user with administrative privileges on the vCenter appliance shell can partially read arbitrary files containing sensitive data.


Affected software

vCenter Server
IBM Cloud Pak System
PowerProtect DP Series Appliance (IDPA)

How to mitigate CVE-2024-22275

Install updates from vendor's website.

vCenter Server - addressed in versions 7.0 U3q, 8.0 U2b
IBM Cloud Pak System - update to 2.3.4.1
PowerProtect DP Series Appliance (IDPA) - update to 2.7.7

External References

Related Security Bulletins