Junglewise Threat Intelligence

CVE-2021-22054: Omnissa Workspace ONE UEM SSRF in management console

CVE-2021-22054 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2026-03-09

Executive brief

Omnissa Workspace ONE UEM (formerly VMware) is a management platform used by organizations to secure and manage mobile devices and applications. A security flaw in the management console allows unauthorized individuals to trick the server into making requests to internal systems or external websites. This could lead to the exposure of sensitive internal information and has been observed being exploited by attackers in the wild.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in the Omnissa Workspace ONE UEM console. The flaw allows a remote, unauthenticated attacker with network access to the UEM console to send crafted requests that the server will execute. This can be used to bypass perimeter security and access internal resources or sensitive data that would otherwise be unreachable. The vulnerability affects multiple versions including 20.0.8, 20.11.0, 21.2.0, and 21.5.0. Patches were released by the vendor to address the issue, and it has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog.

Affected products

  • Omnissa Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, 21.5.0 prior to 21.5.0.37

Timeline

  • 2021-12-17: disclosed: Initial NVD publication date
  • 2021-12-17: patched: VMware released security advisory VMSA-2021-0029
  • 2026-03-09: kev added: Added to CISA Known Exploited Vulnerabilities catalog