CVE-2021-21980
24.11.2021, 17:15
The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.Enginsight
| Vendor | Product | Version |
|---|---|---|
| vmware | cloud_foundation | 3.0 |
| vmware | vcenter_server | 6.5 |
| vmware | vcenter_server | 6.5:update_1 |
| vmware | vcenter_server | 6.5:update_1b |
| vmware | vcenter_server | 6.5:update_1c |
| vmware | vcenter_server | 6.5:update_1d |
| vmware | vcenter_server | 6.5:update_1e |
| vmware | vcenter_server | 6.5:update_1g |
| vmware | vcenter_server | 6.5:update_2 |
| vmware | vcenter_server | 6.5:update_2b |
| vmware | vcenter_server | 6.5:update_2c |
| vmware | vcenter_server | 6.5:update_2d |
| vmware | vcenter_server | 6.5:update_2g |
| vmware | vcenter_server | 6.5:update_3 |
| vmware | vcenter_server | 6.5:update_3d |
| vmware | vcenter_server | 6.5:update_3f |
| vmware | vcenter_server | 6.5:update_3k |
| vmware | vcenter_server | 6.5:update_3n |
| vmware | vcenter_server | 6.5:update_3p |
| vmware | vcenter_server | 6.5:update_3q |
| vmware | vcenter_server | 6.7 |
| vmware | vcenter_server | 6.7:update_1 |
| vmware | vcenter_server | 6.7:update_1b |
| vmware | vcenter_server | 6.7:update_2 |
| vmware | vcenter_server | 6.7:update_2a |
| vmware | vcenter_server | 6.7:update_2c |
| vmware | vcenter_server | 6.7:update_3 |
| vmware | vcenter_server | 6.7:update_3a |
| vmware | vcenter_server | 6.7:update_3b |
| vmware | vcenter_server | 6.7:update_3f |
| vmware | vcenter_server | 6.7:update_3g |
| vmware | vcenter_server | 6.7:update_3j |
| vmware | vcenter_server | 6.7:update_3l |
| vmware | vcenter_server | 6.7:update_3m |
| vmware | vcenter_server | 6.7:update_3n |
| vmware | vcenter_server | 6.7:update_3o |
𝑥
= Vulnerable software versions