Critical Vulnerability in VMware vSphere Plug-in Allows Session Hijacking
Admins are urged to remove vSphere's vulnerable Enhanced Authentication Plug-in, which was discontinued nearly three years ago but is still widely in use.
Vmware Esxi Vcenter Server Microsoft Active Directory Federation Services Cloud Foundation Vmware Service Enhanced Authentication Plug In
Source: darkreading.com