Issued: Tuesday, 5 October, 2021 |
Last Revision: Tuesday, 5 October, 2021 |
Vendor: |
Product: |
Severity Level: |
Summary:
VMware published a security advisory addressing 19 vulnerabilities impacte VMware vCenter Server (vCenter Server) and VMware Cloud Foundation (Cloud Foundation).
In addition to VMware has confirmed reports that CVE-2021-22005 is being exploited in the wild.
CVE | Description | CVSS3.0 Score |
CVE-2021-22005 | vCenter Server file upload vulnerability | 9.8 |
| CVE-2021-21991 | vCenter Server local privilege escalation vulnerability | 8.8 |
| CVE-2021-22006 | vCenter Server reverse proxy bypass vulnerability | 8.3 |
| CVE-2021-22011 | vCenter server unauthenticated API endpoint vulnerability | 8.1 |
| CVE-2021-22015 | vCenter Server improper permission local privilege escalation vulnerabilities | 7.8 |
| CVE-2021-22012 | vCenter Server unauthenticated API information disclosure vulnerability | 7.5 |
| CVE-2021-22013 | vCenter Server file path traversal vulnerability | 7.5 |
| CVE-2021-22016 | vCenter Server reflected XSS vulnerability | 7.5 |
| CVE-2021-22017 | vCenter Server rhttpproxy bypass vulnerability | 7.3 |
| CVE-2021-22014 | vCenter Server authenticated code execution vulnerability | 7.2 |
| CVE-2021-22018 | vCenter Server file deletion vulnerability | 6.5 |
| CVE-2021-21992 | vCenter Server XML parsing denial-of-service | 6.5 |
| CVE-2021-22007 | vCenter Server local information disclosure vulnerability | 5.5 |
| CVE-2021-22019 | vCenter Server denial of service vulnerability | 5.3 |
| CVE-2021-22009 | vCenter Server VAPI multiple denial of service vulnerabilities | 5.3 |
| CVE-2021-22010 | vCenter Server VPXD denial of service vulnerability | 5.3 |
| CVE-2021-22008 | vCenter Server information disclosure vulnerability | 5.3 |
| CVE-2021-22020 | vCenter Server Analytics service denial-of-service Vulnerability | 5.0 |
| CVE-2021-21993 | vCenter Server SSRF vulnerability | 4.3 |
Table 1: Vulnerability details
Recommendation:
Organization using affected products are advised to immediately apply the vendor updates.
