Skip to main content

VMware vCenter Server Vulnerability

Last Update Date: 17 Sep 2015 09:33 Release Date: 17 Sep 2015 3988 Views

RISK: High Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

A vulnerability was identified in VMware vCenter server. A remote user can expolit this vulnerability to bypass TLS certificates validation on the target system when binding to an LDAP server.

 

A remote user that can conduct a man-in-the-middle attack can intercept network traffic between the LDAP server and the target system.


Impact

  • Security Restriction Bypass
  • Information Disclosure
  • Data Manipulation

System / Technologies affected

  • Version prior to 5.5 update 3 (5.5.x )
  • Version prior to 6.0 update 1 (6.0.x)

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix.

Vulnerability Identifier


Source


Related Link