Information disclosure in vCenter Server - CVE-2021-22007
Published: September 21, 2021
Vulnerability identifier: #VU56796
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2021-22007
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output in the Analytics service. A local user can gain unauthorized access to sensitive information on the system.
Affected software
vCenter Server
Dell Enterprise Hybrid Cloud
EMC Integrated Data Protection Appliance
Cloud Foundation
Dell EMC VxRail Appliance
Dell Enterprise Hybrid Cloud
EMC Integrated Data Protection Appliance
Cloud Foundation
Dell EMC VxRail Appliance
How to mitigate CVE-2021-22007
Install updates from vendor's website.
vCenter Server - addressed in versions 6.7 U3o, 7.0 U2c
EMC Integrated Data Protection Appliance - update to 2.7.0
Cloud Foundation - update to 3.10.2.2
Dell Enterprise Hybrid Cloud - update to 4.1.2
Dell EMC VxRail Appliance - addressed in versions 4.5.463, 4.7.536, 7.0.241
EMC Integrated Data Protection Appliance - update to 2.7.0
Cloud Foundation - update to 3.10.2.2
Dell Enterprise Hybrid Cloud - update to 4.1.2
Dell EMC VxRail Appliance - addressed in versions 4.5.463, 4.7.536, 7.0.241
External References
Related Security Bulletins
- Multiple vulnerabilities in VMware vCenter Server
- Multiple vulnerabilities in VMware vCloud Foundation
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Dell EMC Enterprise Hybrid Cloud update for VMware products
- Multiple vulnerabilities in Dell EMC PowerProtect DP Series (Integrated Data Protection Appliance)