CVE-2021-21980
24.11.2021, 17:15
The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.Enginsight
Vendor | Product | Version |
---|---|---|
vmware | cloud_foundation | 3.0 |
vmware | vcenter_server | 6.5 |
vmware | vcenter_server | 6.5:update_1 |
vmware | vcenter_server | 6.5:update_1b |
vmware | vcenter_server | 6.5:update_1c |
vmware | vcenter_server | 6.5:update_1d |
vmware | vcenter_server | 6.5:update_1e |
vmware | vcenter_server | 6.5:update_1g |
vmware | vcenter_server | 6.5:update_2 |
vmware | vcenter_server | 6.5:update_2b |
vmware | vcenter_server | 6.5:update_2c |
vmware | vcenter_server | 6.5:update_2d |
vmware | vcenter_server | 6.5:update_2g |
vmware | vcenter_server | 6.5:update_3 |
vmware | vcenter_server | 6.5:update_3d |
vmware | vcenter_server | 6.5:update_3f |
vmware | vcenter_server | 6.5:update_3k |
vmware | vcenter_server | 6.5:update_3n |
vmware | vcenter_server | 6.5:update_3p |
vmware | vcenter_server | 6.5:update_3q |
vmware | vcenter_server | 6.7 |
vmware | vcenter_server | 6.7:update_1 |
vmware | vcenter_server | 6.7:update_1b |
vmware | vcenter_server | 6.7:update_2 |
vmware | vcenter_server | 6.7:update_2a |
vmware | vcenter_server | 6.7:update_2c |
vmware | vcenter_server | 6.7:update_3 |
vmware | vcenter_server | 6.7:update_3a |
vmware | vcenter_server | 6.7:update_3b |
vmware | vcenter_server | 6.7:update_3f |
vmware | vcenter_server | 6.7:update_3g |
vmware | vcenter_server | 6.7:update_3j |
vmware | vcenter_server | 6.7:update_3l |
vmware | vcenter_server | 6.7:update_3m |
vmware | vcenter_server | 6.7:update_3n |
vmware | vcenter_server | 6.7:update_3o |
𝑥
= Vulnerable software versions