cbcvebase.
CVE-2021-22018
published 2021-09-23

CVE-2021-22018: The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to…

medium6.5CVSS 3.1
AVNACLPRNUINSUCNILAL
The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to port 9087 on vCenter Server may exploit this issue to delete non critical files.

Affected

2 ranges
VendorProductVersion rangeFixed in
vmwarecloud_foundation>= 4.0 < 4.3.14.3.1
vmwarevcenter_server