CVE-2022-22982 PUBLISHED

The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on the vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service.

EPSS 0.25% · 47.7th percentile

Risk Scores

EPSS Score
0.25%
47.7th percentile

Affected Products

VendorProductVersions
vmwarevcenter_server7.0, 7.0, 7.0
vmwarecloud_foundation3.0, 4.0
n/aVMware vCenter ServerVMware vCenter Server (7.0 before 7.0 U3f, 6.7 before 6.7 U3r & 6.5 before 6.5 U3t)

Timeline

References

Open in Interactive Console →