CVE-2012-1513

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
16/03/2012
Last modified:
11/04/2025

Description

The Web Configuration tool in VMware vCenter Orchestrator (vCO) 4.0 before Update 4, 4.1 before Update 2, and 4.2 before Update 1 places the vCenter Server password in an HTML document, which allows remote authenticated administrators to obtain sensitive information by reading this document.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:vcenter_orchestrator:4.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:vcenter_orchestrator:4.1:*:*:*:*:*:*:*