|
194971
|
5.3 |
MEDIUM
Network
|
vmware
|
vcenter_server
|
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this …
|
NVD-CWE-noinfo
|
CVE-2021-22017
|
2024-11-21 14:49 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194972
|
6.1 |
MEDIUM
Network
|
vmware
|
vcenter_server cloud_foundation
|
The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attacker may exploit this issue to execute malicious scripts by tricking a victim in…
|
CWE-79
Cross-site Scripting
|
CVE-2021-22016
|
2024-11-21 14:49 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194973
|
7.8 |
HIGH
Local
|
vmware
|
vcenter_server cloud_foundation
|
The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper permissions of files and directories. An authenticated local user with non-administrative privilege may…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2021-22015
|
2024-11-21 14:49 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194974
|
7.2 |
HIGH
Network
|
vmware
|
vcenter_server cloud_foundation
|
The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastructure). An authenticated VAMI user with network access to port 5480 on vCenter…
|
NVD-CWE-noinfo
|
CVE-2021-22014
|
2024-11-21 14:49 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194975
|
7.5 |
HIGH
Network
|
vmware
|
vcenter_server cloud_foundation
|
The vCenter Server contains a file path traversal vulnerability leading to information disclosure in the appliance management API. A malicious actor with network access to port 443 on vCenter Server …
|
CWE-22
Path Traversal
|
CVE-2021-22013
|
2024-11-21 14:49 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194976
|
7.5 |
HIGH
Network
|
vmware
|
vcenter_server cloud_foundation
|
The vCenter Server contains an information disclosure vulnerability due to an unauthenticated appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-22012
|
2024-11-21 14:49 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194977
|
5.3 |
MEDIUM
Network
|
vmware
|
vcenter_server cloud_foundation
|
vCenter Server contains an unauthenticated API endpoint vulnerability in vCenter Server Content Library. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to …
|
NVD-CWE-noinfo
|
CVE-2021-22011
|
2024-11-21 14:49 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194978
|
7.5 |
HIGH
Network
|
vmware
|
vcenter_server cloud_foundation
|
The vCenter Server contains a denial-of-service vulnerability in VPXD service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to create a denial of service…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2021-22010
|
2024-11-21 14:49 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194979
|
7.5 |
HIGH
Network
|
vmware
|
vcenter_server cloud_foundation
|
The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit these issues to c…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2021-22009
|
2024-11-21 14:49 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194980
|
7.5 |
HIGH
Network
|
vmware
|
vcenter_server cloud_foundation
|
The vCenter Server contains an information disclosure vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by sendin…
|
NVD-CWE-noinfo
|
CVE-2021-22008
|
2024-11-21 14:49 |
2021-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|