/Vulnerability Library

vCenter Server - Improper Access Control

CVE-2021-22017
Verified

Description

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.

Severity

Medium

CVSS Score

5.3

Exploit Probability

49%

Affected Product

vcenter_server

Published Date

January 14, 2026

Template Author

daffainfo

CVE-2021-22017.yaml
5.3Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE ID:
cve-2021-22017
CWE ID:
nvd-cwe-noinfo

References

https://github.com/wangsir01/docs/blob/7c20bbf43ae467c1bdc54c65c9a3230ae3e81d63/CVE-2021-22017-22005%E6%A8%A1%E6%9D%BF%E6%B3%A8%E5%85%A5%E5%88%86%E6%9E%90/CVE-2021-22017-22005%E6%A8%A1%E6%9D%BF%E6%B3%A8%E5%85%A5%E5%88%86%E6%9E%90.mdhttps://www.vmware.com/security/advisories/VMSA-2021-0020.htmlhttps://nvd.nist.gov/vuln/detail/CVE-2021-22017

Remediation Steps

Apply the latest security patches or updates provided by VMware for vCenter Server.