CVE-2022-22948 - CVE House
Back to Database
Status published Unknown CVE-2022-22948

The vCenter Server contains an information disclosure vulnerability due to...

Vulnerability Description

The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-22948

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

VMware vCenter Server and VMware Cloud Foundation
Vulnerable Versions:
VMware vCenter Server (7.0 prior to 7.0 U3d, 6.7 prior to 6.7 U3p and 6.5 prior to 6.5 U3r) and VMware Cloud Foundation (4.x and 3.x prior to 3.11)

Timeline

Official Publish: March 29th, 2022
Last Modified: October 21st, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.