#VU21148 Cleartext storage of sensitive information in vCenter Server - CVE-2019-5532
Published: September 17, 2019
vCenter Server
VMware, Inc
Description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to VMware vCenter Server logs user credentials of guest operating system in plain text when deployed through OVF. A local user of the host operating system is able to read log files and gain superuser credentials of deployed guest operating systems.