CVE-2021-22013: Path Traversal
Published Sep 23, 2021
·Updated
The vCenter Server contains a file path traversal vulnerability leading to information disclosure in the appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.
Affected Software
3 affected components
VMware Cloud Foundation>=3.0<5.0
VMware vCenter Server=6.7
VMware vCenter Server=7.0
Remediation
Event History
Sep 23, 2021
CVE Published
via MITRE·11:58 AM
Data Sourced
via MITRE·11:58 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-22013?
CVE-2021-22013 is a file path traversal vulnerability in vCenter Server that can lead to information disclosure.
2
How does CVE-2021-22013 affect VMware Cloud Foundation?
VMware Cloud Foundation versions 3.0 to 5.0 are affected by CVE-2021-22013.
3
Which versions of VMware vCenter Server are affected by CVE-2021-22013?
CVE-2021-22013 affects VMware vCenter Server versions 6.7 and 7.0.
4
What is the severity of CVE-2021-22013?
CVE-2021-22013 has a severity rating of 7.5 (High).
5
How can CVE-2021-22013 be mitigated?
Apply the necessary patches and updates provided by VMware to fix the vulnerability.