CVE-2021-22049
Severity CVSS v4.0:
Pending analysis
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
24/11/2021
Last modified:
30/11/2021
Description
The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:vmware:vcenter_server:6.5:-:*:*:*:*:*:* | ||
| cpe:2.3:a:vmware:vcenter_server:6.7:-:*:*:*:*:*:* | ||
| cpe:2.3:a:vmware:vcenter_server:7.0:-:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



