CVE-2021-22001
Status: ModifiedHigh (7.5)—
In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion request of an identity provider( IdP) of type “oauth 1.0” was sent to UAA server.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.99%
- Percentile among all scored CVEs: 61
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (2)
CWEs
- CWE-200
- NVD-CWE-noinfo
References
Raw JSON (NVD)
Show
{
"id": "CVE-2021-22001",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@vmware.com",
"affectedData": [
{
"vendor": "n/a",
"product": "Cloud Foundry UAA server",
"versions": [
{
"status": "affected",
"version": "Cloud Foundry UAA server prior to version 75.3.0"
}
]
}
]
}
],
"published": "2021-07-22T14:15:07.867",
"references": [
{
"url": "https://www.cloudfoundry.org/blog/cve-2021-22001-sensitive-info-leakage-in-uaa-during-identity-provider-deletion/",
"tags": [
"Vendor Advisory"
],
"source": "security@vmware.com"
},
{
"url": "https://www.cloudfoundry.org/blog/cve-2021-22001-sensitive-info-leakage-in-uaa-during-identity-provider-deletion/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security@vmware.com",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion request of an identity provider( IdP) of type “oauth 1.0” was sent to UAA server."
},
{
"lang": "es",
"value": "En UAA versiones anteriores a 75.3.0, se ha revelado información confidencial como el secreto de retransmisión del proveedor en respuesta cuando se enviaba al servidor de UAA una petición de eliminación de un proveedor de identidades (IdP) de tipo \"oauth 1.0\""
}
],
"lastModified": "2026-06-17T03:36:32.020",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "659D136D-133F-4418-BD5C-A1A931BCB412",
"versionEndExcluding": "16.18.0"
},
{
"criteria": "cpe:2.3:a:cloudfoundry:user_account_and_authentication:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CB67B221-E6CB-482B-B175-0AD5284CF058",
"versionEndExcluding": "75.3.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@vmware.com"
}