← Back to CVE List

CVE-2021-22049

Published: 2021-11-24T17:15Z
Last Modified: 2024-11-21T05:49Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt