PT-2021-4316 · Vmware · Vcenter Server+1

George Noseevich

+2

·

Published

2021-09-23

·

Updated

2026-02-04

·

CVE-2021-22017

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions vCenter Server (affected versions not specified)
Description The issue is related to improper implementation of URI normalization in the rhttproxy service used by vCenter Server. This allows a malicious actor with network access to port 443 on vCenter Server to exploit the issue and bypass proxy, leading to internal endpoints being accessed. The vulnerability is also described as an improper access control issue, which can be exploited by a remote attacker to bypass existing security restrictions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Weakness Enumeration

Related Identifiers

BDU:2021-04925
CVE-2021-22017

Affected Products

Vmware Vcenter
Vcenter Server