CVE-2021-22008
23.09.2021, 12:15
The vCenter Server contains an information disclosure vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by sending a specially crafted json-rpc message to gain access to sensitive information.Enginsight
Vendor | Product | Version |
---|---|---|
vmware | cloud_foundation | 3.0 ≤ 𝑥 < 5.0 |
vmware | vcenter_server | 6.5 |
vmware | vcenter_server | 6.7 |
vmware | vcenter_server | 7.0 |
𝑥
= Vulnerable software versions