Information disclosure in vCenter Server - CVE-2021-22007

 

Information disclosure in vCenter Server - CVE-2021-22007

Published: September 21, 2021


Vulnerability identifier: #VU56796
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2021-22007
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in the Analytics service. A local user can gain unauthorized access to sensitive information on the system.


Affected software

vCenter Server
Dell Enterprise Hybrid Cloud
EMC Integrated Data Protection Appliance
Cloud Foundation
Dell EMC VxRail Appliance

How to mitigate CVE-2021-22007

Install updates from vendor's website.

vCenter Server - addressed in versions 6.7 U3o, 7.0 U2c
EMC Integrated Data Protection Appliance - update to 2.7.0
Cloud Foundation - update to 3.10.2.2
Dell Enterprise Hybrid Cloud - update to 4.1.2
Dell EMC VxRail Appliance - addressed in versions 4.5.463, 4.7.536, 7.0.241

External References

Related Security Bulletins