Executive brief
Rhttproxy in VMware vCenter Server contains a vulnerability due to improper URI normalization. A malicious actor with network access to port 443 can bypass the proxy to access internal endpoints.
Affected products
- VMware vCenter Server 6.7
Timeline
- 2021-09-23: disclosed
- 2022-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog