CVE-2021-22007: Medium severity vmware vcenter server and cloud foundation vulnerability
The vCenter Server contains a local information disclosure vulnerability in the Analytics service. An authenticated user with non-administrative privilege may exploit this issue to gain access to sensitive information.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-22007?
CVE-2021-22007 is a local information disclosure vulnerability in the Analytics service of vCenter Server.
How can an attacker exploit CVE-2021-22007?
An authenticated user with non-administrative privilege may exploit this vulnerability to gain access to sensitive information.
Which versions of VMware Cloud Foundation are affected by CVE-2021-22007?
VMware Cloud Foundation versions 3.0 to 5.0 are affected by CVE-2021-22007.
Which versions of VMware vCenter Server are affected by CVE-2021-22007?
VMware vCenter Server versions 6.7 and 7.0 are affected by CVE-2021-22007.
What is the severity rating of CVE-2021-22007?
CVE-2021-22007 has a severity rating of medium with a CVSS score of 5.5.
Where can I find more information about CVE-2021-22007?
For more information about CVE-2021-22007, you can refer to the VMware Security Advisory VMSA-2021-0020.