CVE-2021-22016: XSS
Published Sep 23, 2021
·Updated
The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attacker may exploit this issue to execute malicious scripts by tricking a victim into clicking a malicious link.
Affected Software
2 affected components
VMware Cloud Foundation>=3.0<5.0
VMware vCenter Server=6.7
Remediation
Event History
Sep 23, 2021
CVE Published
via MITRE·12:12 PM
Data Sourced
via MITRE·12:12 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-22016?
CVE-2021-22016 is a reflected cross-site scripting vulnerability in vCenter Server.
2
How does CVE-2021-22016 affect VMware vCenter Server?
CVE-2021-22016 affects VMware vCenter Server 6.7.
3
What is the severity of CVE-2021-22016?
The severity of CVE-2021-22016 is medium with a CVSS score of 6.1.
4
How can CVE-2021-22016 be exploited?
CVE-2021-22016 can be exploited by tricking a victim into clicking a malicious link.
5
Is there a fix for CVE-2021-22016?
Yes, VMware has released a security advisory (VMSA-2021-0020) that includes fixes and mitigations for CVE-2021-22016.