CVE-2021-22005
- EPSS 94.46%
- Published 23.09.2021 12:15:07
- Last modified 02.04.2025 16:59:19
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted...
CVE-2021-22006
- EPSS 47.06%
- Published 23.09.2021 12:15:07
- Last modified 21.11.2024 05:49:25
The vCenter Server contains a reverse proxy bypass vulnerability due to the way the endpoints handle the URI. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to access restricted endpoints.
CVE-2021-22007
- EPSS 0.07%
- Published 23.09.2021 12:15:07
- Last modified 21.11.2024 05:49:25
The vCenter Server contains a local information disclosure vulnerability in the Analytics service. An authenticated user with non-administrative privilege may exploit this issue to gain access to sensitive information.
CVE-2021-22008
- EPSS 0.5%
- Published 23.09.2021 12:15:07
- Last modified 21.11.2024 05:49:25
The vCenter Server contains an information disclosure vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by sending a specially crafted json-rpc message to gain acce...
CVE-2021-22009
- EPSS 1.47%
- Published 23.09.2021 12:15:07
- Last modified 21.11.2024 05:49:25
The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit these issues to create a denial of service condition due to excessiv...
CVE-2021-22010
- EPSS 1.07%
- Published 23.09.2021 12:15:07
- Last modified 21.11.2024 05:49:26
The vCenter Server contains a denial-of-service vulnerability in VPXD service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to create a denial of service condition due to excessive memory consumption by V...
CVE-2021-22011
- EPSS 0.59%
- Published 23.09.2021 12:15:07
- Last modified 21.11.2024 05:49:26
vCenter Server contains an unauthenticated API endpoint vulnerability in vCenter Server Content Library. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to perform unauthenticated VM network setting manipula...
CVE-2021-21991
- EPSS 0.1%
- Published 22.09.2021 19:15:09
- Last modified 21.11.2024 05:49:23
The vCenter Server contains a local privilege escalation vulnerability due to the way it handles session tokens. A malicious actor with non-administrative user access on vCenter Server host may exploit this issue to escalate privileges to Administrat...
CVE-2021-21992
- EPSS 0.49%
- Published 22.09.2021 19:15:09
- Last modified 21.11.2024 05:49:23
The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with non-administrative user access to the vCenter Server vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash) may...
CVE-2021-22002
- EPSS 0.4%
- Published 31.08.2021 22:15:08
- Last modified 21.11.2024 05:49:25
VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443 could tamper with host headers ...