The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-9216 The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2024-08-03T18:30:24.029Z

Reserved: 2021-01-04T00:00:00

Link: CVE-2021-22049

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-11-24T17:15:07.707

Modified: 2024-11-21T05:49:30.077

Link: CVE-2021-22049

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses