CVE-2012-1513: VMware vCenter Orchestrator

Medium severity, CVSS 4.0. EPSS: 1.2% chance of exploitation in the next 30 days.

The Web Configuration tool in VMware vCenter Orchestrator (vCO) 4.0 before Update 4, 4.1 before Update 2, and 4.2 before Update 1 places the vCenter Server password in an HTML document, which allows remote authenticated administrators to obtain sensitive information by reading this document.

Affected products

  • VMware vCenter Orchestrator: version 4.0 only; version 4.1 only

Published 2012-03-16. Last modified 2026-06-16.