CVE-2021-22018
published 2021-09-23CVE-2021-22018: The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to…
medium6.5CVSS 3.1
AVNACLPRNUINSUCNILAL
The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to port 9087 on vCenter Server may exploit this issue to delete non critical files.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | >= 4.0 < 4.3.1 | 4.3.1 |
| vmware | vcenter_server | — | — |