Junglewise Threat Intelligence

CVE-2021-21975: VMware Server Side Request Forgery in vRealize Operations Manager API

CVE-2021-21975 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2022-01-18

Vendors: VMware.

Executive brief

A Server Side Request Forgery (SSRF) vulnerability in the VMware vRealize Operations Manager API allows an unauthenticated attacker with network access to perform unauthorized requests. This flaw can be leveraged to steal administrative credentials.

Affected products

  • VMware vRealize Operations Manager prior to 8.4

Timeline

  • 2021-03-30: advisory: VMware VMSA-2021-0004 published (referenced in history)
  • 2022-01-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-01-18: disclosed