VMware Cloud Community
TheVMinator
Expert
Expert
Jump to solution

SSO and Vulnerabilities

I have a few accounts in SSO that have full privileges to do anything in SSO. However only adminstrator@vsphere.local has any permissions in vCenter Server.  Do the accounts that have full privileges in SSO, but are not given any privileges in vCenter, represent a vulnerability to vCenter if compromised, or just to SSO?

0 Kudos
1 Solution

Accepted Solutions
mikefoley
VMware Employee
VMware Employee
Jump to solution

If you have an account with full privileges in SSO then even if they don't have permissions on vCenter they could compromise the administrator@vsphere.local account (change password for example) and get full access.

mike

mike

View solution in original post

0 Kudos
3 Replies
Texiwill
Leadership
Leadership
Jump to solution

Hello,

I would think just to SSO. But I think we should get another opinion here.

Best regards,
Edward L. Haletky
VMware Communities User Moderator, VMware vExpert 2009, 2010, 2011,2012,2013,2014

Author of the books 'VMWare ESX and ESXi in the Enterprise: Planning Deployment Virtualization Servers', Copyright 2011 Pearson Education. 'VMware vSphere and Virtual Infrastructure Security: Securing the Virtual Environment', Copyright 2009 Pearson Education.

Virtualization and Cloud Security Analyst: The Virtualization Practice, LLC -- vSphere Upgrade Saga -- Virtualization Security Round Table Podcast

--
Edward L. Haletky
vExpert XIV: 2009-2023,
VMTN Community Moderator
vSphere Upgrade Saga: https://www.astroarch.com/blogs
GitHub Repo: https://github.com/Texiwill
0 Kudos
mikefoley
VMware Employee
VMware Employee
Jump to solution

If you have an account with full privileges in SSO then even if they don't have permissions on vCenter they could compromise the administrator@vsphere.local account (change password for example) and get full access.

mike

mike

0 Kudos
TheVMinator
Expert
Expert
Jump to solution

Thanks!

0 Kudos