CVE-2021-22017: VMware vCenter Server Improper Access Control
Published Sep 23, 2021
·Updated
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.
Affected Software
2 affected components
VMware vCenter Server
VMware vCenter Server=6.7
Remediation
Event History
Sep 23, 2021
CVE Published
via MITRE·12:13 PM
Data Sourced
via MITRE·12:13 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
RemedyDescriptionSeverityAffected Software
Jan 10, 2022
Known Exploited
via CISA·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2021-22017.
2
What is the title of this vulnerability?
The title of this vulnerability is 'VMware vCenter Server Improper Access Control'.
3
What is the description of this vulnerability?
The vulnerability in vCenter Server allows a malicious actor to bypass proxy and access internal endpoints due to improper implementation of URI normalization.
4
What software is affected by this vulnerability?
vCenter Server version 6.7 is affected by this vulnerability.
5
What is the severity of CVE-2021-22017?
The severity of CVE-2021-22017 is medium with a CVSS score of 5.3.
6
How can I fix this vulnerability in VMware vCenter Server?
To fix this vulnerability, apply the necessary patches and updates provided by VMware. Refer to the VMware Security Advisory VMSA-2021-0020 for more information.