VDB
CVE-2022-22982
CVE-2022-22982
PUBLISHED
The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on the vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service.
EPSS 0.25% · 48.1th percentile
Risk Scores
EPSS Score
0.25%
48.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| vmware | vcenter_server | 7.0, 6.5, 6.5 |
| vmware | cloud_foundation | 4.0, 3.0 |
| n/a | VMware vCenter Server | VMware vCenter Server (7.0 before 7.0 U3f, 6.7 before 6.7 U3r & 6.5 before 6.5 U3t) |
Exploit Intelligence
Timeline
- Jul 13, 2022 CVE Published
- Jul 15, 2022 EPSS Score
- Aug 31, 2022 EPSS Score
- Oct 17, 2022 EPSS Score
- Dec 3, 2022 EPSS Score
- Jan 19, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 23, 2023 EPSS Score
- Jun 9, 2023 EPSS Score
- Jul 27, 2023 EPSS Score
- Sep 12, 2023 EPSS Score
- Oct 29, 2023 EPSS Score
References
- https://www.vmware.com/security/advisories/VMSA-2022-0018.html url
- https://nvd.nist.gov/vuln/detail/CVE-2022-22982 advisory
- https://www.vmware.com/security/advisories/VMSA-2022-0020.html advisory
- https://www.vmware.com/security/advisories/VMSA-2022-0019.html advisory
- https://www.vmware.com/security/advisories/VMSA-2021-0025.html advisory