CVE-2012-1472: VMware vCenter Chargeback Manager

Medium severity, CVSS 6.4. EPSS: 1.9% chance of exploitation in the next 30 days.

VMware vCenter Chargeback Manager (aka CBM) before 2.0.1 does not properly handle XML API requests, which allows remote attackers to read arbitrary files or cause a denial of service via unspecified vectors.

Affected products

  • VMware vCenter Chargeback Manager: up to and including 2.0.0; version 1.6.2 only

Published 2012-03-13. Last modified 2026-06-16.