← Back to browse · API

CVE-2021-22017

Severity
MEDIUM
CVSS
5.3
EPSS
0.49177
Risk score
63.41
CISA KEV
Yes
PoC
No
Published
2021-09-23
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2021-9186, GHSA-W46J-W72R-9X98
Products
VMware:vCenter Server, n/a:VMware vCenter Server, VMware Cloud Foundation VMware vCenter Server(6.7 before 6.7 U3o and 6.5 before 6.5 U3q) and VMware Cloud Foundation 3.x before 3.10.2.2
Sources
cisa.gov CVE-2021-22017
euvd EUVD-2021-9186

Description

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.

References