CVE-2022-22982
Published on: Not Yet Published
Last Modified on: 07/20/2022 03:11:00 PM UTC
Certain versions of Cloud Foundation from Vmware contain the following vulnerability:
The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on the vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service.
- CVE-2022-22982 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
VMSA-2022-0018 | www.vmware.com text/html |
![]() |
Related QID Numbers
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Vmware | Cloud Foundation | All | All | All | All |
Application | Vmware | Cloud Foundation | All | All | All | All |
Application | Vmware | Vcenter Server | 6.5 | - | All | All |
Application | Vmware | Vcenter Server | 6.5 | a | All | All |
Application | Vmware | Vcenter Server | 6.5 | b | All | All |
Application | Vmware | Vcenter Server | 6.5 | c | All | All |
Application | Vmware | Vcenter Server | 6.5 | d | All | All |
Application | Vmware | Vcenter Server | 6.5 | e | All | All |
Application | Vmware | Vcenter Server | 6.5 | f | All | All |
Application | Vmware | Vcenter Server | 6.5 | update1 | All | All |
Application | Vmware | Vcenter Server | 6.5 | update1b | All | All |
Application | Vmware | Vcenter Server | 6.5 | update1c | All | All |
Application | Vmware | Vcenter Server | 6.5 | update1d | All | All |
Application | Vmware | Vcenter Server | 6.5 | update1e | All | All |
Application | Vmware | Vcenter Server | 6.5 | update1g | All | All |
Application | Vmware | Vcenter Server | 6.5 | update2 | All | All |
Application | Vmware | Vcenter Server | 6.5 | update2b | All | All |
Application | Vmware | Vcenter Server | 6.5 | update2c | All | All |
Application | Vmware | Vcenter Server | 6.5 | update2d | All | All |
Application | Vmware | Vcenter Server | 6.5 | update2g | All | All |
Application | Vmware | Vcenter Server | 6.5 | update3 | All | All |
Application | Vmware | Vcenter Server | 6.5 | update3d | All | All |
Application | Vmware | Vcenter Server | 6.5 | update3f | All | All |
Application | Vmware | Vcenter Server | 6.5 | update3k | All | All |
Application | Vmware | Vcenter Server | 6.5 | update3n | All | All |
Application | Vmware | Vcenter Server | 6.5 | update3p | All | All |
Application | Vmware | Vcenter Server | 6.5 | update3q | All | All |
Application | Vmware | Vcenter Server | 6.5 | update3r | All | All |
Application | Vmware | Vcenter Server | 6.5 | update3s | All | All |
Application | Vmware | Vcenter Server | 6.7 | - | All | All |
Application | Vmware | Vcenter Server | 6.7 | a | All | All |
Application | Vmware | Vcenter Server | 6.7 | b | All | All |
Application | Vmware | Vcenter Server | 6.7 | d | All | All |
Application | Vmware | Vcenter Server | 6.7 | update1 | All | All |
Application | Vmware | Vcenter Server | 6.7 | update1b | All | All |
Application | Vmware | Vcenter Server | 6.7 | update2 | All | All |
Application | Vmware | Vcenter Server | 6.7 | update2a | All | All |
Application | Vmware | Vcenter Server | 6.7 | update2c | All | All |
Application | Vmware | Vcenter Server | 6.7 | update3 | All | All |
Application | Vmware | Vcenter Server | 6.7 | update3a | All | All |
Application | Vmware | Vcenter Server | 6.7 | update3b | All | All |
Application | Vmware | Vcenter Server | 6.7 | update3f | All | All |
Application | Vmware | Vcenter Server | 6.7 | update3g | All | All |
Application | Vmware | Vcenter Server | 6.7 | update3j | All | All |
Application | Vmware | Vcenter Server | 6.7 | update3l | All | All |
Application | Vmware | Vcenter Server | 6.7 | update3m | All | All |
Application | Vmware | Vcenter Server | 6.7 | update3n | All | All |
Application | Vmware | Vcenter Server | 6.7 | update3o | All | All |
Application | Vmware | Vcenter Server | 6.7 | update3p | All | All |
Application | Vmware | Vcenter Server | 6.7 | update3q | All | All |
Application | Vmware | Vcenter Server | 7.0 | - | All | All |
Application | Vmware | Vcenter Server | 7.0 | a | All | All |
Application | Vmware | Vcenter Server | 7.0 | b | All | All |
Application | Vmware | Vcenter Server | 7.0 | c | All | All |
Application | Vmware | Vcenter Server | 7.0 | d | All | All |
Application | Vmware | Vcenter Server | 7.0 | update1 | All | All |
Application | Vmware | Vcenter Server | 7.0 | update1a | All | All |
Application | Vmware | Vcenter Server | 7.0 | update1c | All | All |
Application | Vmware | Vcenter Server | 7.0 | update1d | All | All |
Application | Vmware | Vcenter Server | 7.0 | update2 | All | All |
Application | Vmware | Vcenter Server | 7.0 | update2a | All | All |
Application | Vmware | Vcenter Server | 7.0 | update2b | All | All |
Application | Vmware | Vcenter Server | 7.0 | update2c | All | All |
Application | Vmware | Vcenter Server | 7.0 | update2d | All | All |
Application | Vmware | Vcenter Server | 7.0 | update3 | All | All |
Application | Vmware | Vcenter Server | 7.0 | update3a | All | All |
Application | Vmware | Vcenter Server | 7.0 | update3c | All | All |
Application | Vmware | Vcenter Server | 7.0 | update3d | All | All |
Application | Vmware | Vcenter Server | 7.0 | update3e | All | All |
- cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*:
- cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:-:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:a:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:b:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:c:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:d:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:e:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:f:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:update1:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:update1b:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:update1c:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:update1d:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:update1e:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:update1g:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:update2:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:update2b:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:update2c:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:update2d:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:update2g:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:update3:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:update3d:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:update3f:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:update3k:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:update3n:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:update3p:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:update3q:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:update3r:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.5:update3s:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.7:-:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.7:a:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.7:b:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.7:d:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.7:update1:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.7:update1b:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.7:update2:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.7:update2a:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.7:update2c:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.7:update3:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.7:update3a:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.7:update3b:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.7:update3f:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.7:update3g:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.7:update3j:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.7:update3l:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.7:update3m:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.7:update3n:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.7:update3o:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.7:update3p:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:6.7:update3q:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:7.0:-:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:7.0:a:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:7.0:b:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:7.0:c:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:7.0:d:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:7.0:update1:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:7.0:update1a:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:7.0:update1c:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:7.0:update1d:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:7.0:update2:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:7.0:update2a:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:7.0:update2b:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:7.0:update2c:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:7.0:update2d:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:7.0:update3:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:7.0:update3a:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:7.0:update3c:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:7.0:update3d:*:*:*:*:*:*:
- cpe:2.3:a:vmware:vcenter_server:7.0:update3e:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
VMware vCenter Server にサーバサイドリクエストフォージェリの問題 (CVE-2022-22982) [42739] sid.softek.jp/content/show/4… #SIDfm #脆弱性情報 | 2022-07-13 05:00:03 |
![]() |
CVE-2022-22982 : The vCenter Server contains a server-side request forgery #SSRF vulnerability. A malicious actor… twitter.com/i/web/status/1… | 2022-07-13 19:14:22 |
![]() |
CVE-2022-22982 | 2022-07-13 19:38:22 |