QID 216275
Date Published: 2021-12-16
QID 216275: VMware vCenter Server 7.0 Apache Log4j Remote Code Execution (RCE) Vulnerability (VMSA-2021-0028)
VMware vCenter Server is a server management solution that helps IT admins manage virtualized hosts and virtual machines in enterprise environments via a single console.
Affected Versions:
VMware vCenter Server 7.0
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of VMware vCenter Server with build version using web service present on the target.
Note: Patch for this vulnerability is not available yet. We are unable to check the workaround through detection, hence this QID is a Potential Vulnerability.
A malicious actor with network access to an impacted VMware product may exploit this issue to gain full control of the target system.
Refer to KB87081 for more information.
- VMSA-2021-0028 -
www.vmware.com/security/advisories/VMSA-2021-0028.html
CVEs related to QID 216275
Advisory ID | Software | Component | Link |
---|