PT-2021-4316 · Vmware · Vcenter Server+1
George Noseevich
+2
·
Published
2021-09-23
·
Updated
2026-02-04
·
CVE-2021-22017
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
vCenter Server (affected versions not specified)
Description
The issue is related to improper implementation of URI normalization in the rhttproxy service used by vCenter Server. This allows a malicious actor with network access to port 443 on vCenter Server to exploit the issue and bypass proxy, leading to internal endpoints being accessed. The vulnerability is also described as an improper access control issue, which can be exploited by a remote attacker to bypass existing security restrictions.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vmware Vcenter
Vcenter Server