CVE-2021-22012: High severity vmware vcenter server and cloud foundation vulnerability
The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-22012?
CVE-2021-22012 is an information disclosure vulnerability in vCenter Server.
What is the severity of CVE-2021-22012?
The severity of CVE-2021-22012 is high.
How does CVE-2021-22012 affect VMware Cloud Foundation?
CVE-2021-22012 affects VMware Cloud Foundation versions 3.0 to 5.0.
How does CVE-2021-22012 affect VMware vCenter Server 6.7?
CVE-2021-22012 affects VMware vCenter Server version 6.7.
How does CVE-2021-22012 affect VMware vCenter Server 7.0?
CVE-2021-22012 affects VMware vCenter Server version 7.0.
How can the information disclosure vulnerability in vCenter Server be exploited?
A malicious actor with network access to port 443 on vCenter Server can exploit the vulnerability to gain access to sensitive information.
Where can I find more information about CVE-2021-22012?
You can find more information about CVE-2021-22012 at the following link: [VMware Security Advisory VMSA-2021-0020](https://www.vmware.com/security/advisories/VMSA-2021-0020.html).
What is CWE-306?
CWE-306 is the Common Weakness Enumeration category for the vulnerability.