Aller au contenu

Fiche vulnérabilité

CVE-2021-22017 : faille exploitée vmware vcenter server (CVSS 5.3)

Description

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.

En bref

Sévérité
Moyenne (CVSS 5.3)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitation active
Oui, inscrite au catalogue CISA KEV
Publication
23 sept. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • vmware vcenter server

Correctif et mesures

Apply updates per vendor instructions.

Références

Rechercher une autre vulnérabilité dans la base CVE