CVE-2021-22017CISA KEVEPSS p98.7%

CVE-2021-22017VMware vCenter Server Improper Access Control

VMware / vCenter Server

Description

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.

Scoring

EPSS46.72% probability of exploitation · percentile 98.7% · 2026-06-18T12:00:27Z

CISA KEV entry

Added to KEV: 2022-01-10

(incoming)1

TypeTargetConfidenceTier
KEVEntryVMware vCenter Server Improper Access Controlkev-cve-2021-220170%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
VMware vCenter Server Incorrect Default File Permissions Vulnerability
CVE
VMware vCenter Server Remote Code Execution Vulnerability
CVE
VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability
CVE
VMware vCenter Server Privilege Escalation Vulnerability
CVE
VMware vCenter Server Information Disclosure Vulnerability
CVE
VMware vCenter Server Improper Input Validation Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.