{"cveID":"CVE-2021-22017","vendorProject":"VMware","product":"vCenter Server","vulnerabilityName":"VMware vCenter Server Improper Access Control","dateAdded":"2022-01-10","shortDescription":"Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-01-24","knownRansomwareCampaignUse":"Unknown","notes":"https://nvd.nist.gov/vuln/detail/CVE-2021-22017","cwes":["CWE-23"],"year":2021,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2021-22017","technique":"T1190","technique_name_at_mapping":"Exploit Public-Facing Application","mapping_type":"exploitation_technique","capability_group":"access_ctrl","comments":"The vulnerability in Rhttproxy within VMware's vCenter Server arises from an improper implementation of URI normalization. Attackers with network access to port 443 on the vCenter Server exploit this flaw by sending specially crafted requests, allowing them to bypass the proxy mechanism. This exploitation grants unauthorized access to internal endpoints, potentially exposing sensitive information.","references":["https://www.securityweek.com/vmware-confirms-wild-exploitation-vcenter-server-vulnerability/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-22017","technique":"T1090.001","technique_name_at_mapping":"Internal Proxy","mapping_type":"primary_impact","capability_group":"access_ctrl","comments":"The vulnerability in Rhttproxy within VMware's vCenter Server arises from an improper implementation of URI normalization. Attackers with network access to port 443 on the vCenter Server exploit this flaw by sending specially crafted requests, allowing them to bypass the proxy mechanism. This exploitation grants unauthorized access to internal endpoints, potentially exposing sensitive information.","references":["https://www.securityweek.com/vmware-confirms-wild-exploitation-vcenter-server-vulnerability/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1090.001","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Internal Proxy","name_at_mapping":"Internal Proxy","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":6,"has_detection_strategy":true},{"id":"T1190","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploit Public-Facing Application","name_at_mapping":"Exploit Public-Facing Application","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":149,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}