Running a Qualys security scan may show a false positive on a vCenter service with this error message:
Qualys Vulnerability Details (VTUID: 1089070, QID: 731802)
Impact
An unauthenticated, remote attacker could log in to the affected endpoint to compromise the confidentiality, integrity and availability as this user has all the rights and permissions.
Threat
ClickHouse is an open-source column-oriented DBMS for online analytical processing (OLAP) that allows users to generate analytical reports using SQL queries in real-time.
An endpoint with ClickHouse DBMS console accepting requests without any credentials was detected.
QID Detection Logic: (Unauthenticated)
This QID tries to query for the DB version and DB schema without any credentials via the web console
vSphere 7.x
vSphere 8.x
The vCenter server does not utilize ClickHouse software so this a false positive.
Engage Qualys to confirm this is a false positive and for further troubleshooting steps.