CVE-2012-1513

medium VMware
CVSS v3 Base Score
4.0
AV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS Score
0.4%
Exploitation probability in 30 days
Top 41% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Confidentiality
P
Integrity
None
Availability
None
Published: March 16, 2012 (5172 days ago)
Last Modified: April 29, 2026
Vendor: VMware
Source: NVD

Description

The Web Configuration tool in VMware vCenter Orchestrator (vCO) 4.0 before Update 4, 4.1 before Update 2, and 4.2 before Update 1 places the vCenter Server password in an HTML document, which allows remote authenticated administrators to obtain sensitive information by reading this document.

CWE

CWE-200

Affected Products

vmware vcenter orchestrator

References