First published: Wed Mar 31 2021(Updated: )
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
Credit: security@vmware.com security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Cloud Foundation | =3.0 | |
VMware Cloud Foundation | =3.0.1 | |
VMware Cloud Foundation | =3.0.1.1 | |
VMware Cloud Foundation | =3.5 | |
VMware Cloud Foundation | =3.5.1 | |
VMware Cloud Foundation | =3.7 | |
VMware Cloud Foundation | =3.7.1 | |
VMware Cloud Foundation | =3.7.2 | |
VMware Cloud Foundation | =3.8 | |
VMware Cloud Foundation | =3.8.1 | |
VMware Cloud Foundation | =3.9 | |
VMware Cloud Foundation | =3.9.1 | |
VMware Cloud Foundation | =3.10 | |
VMware Cloud Foundation | =4.0 | |
VMware Cloud Foundation | =4.0.1 | |
Vmware Vrealize Operations Manager | =7.0.0 | |
Vmware Vrealize Operations Manager | =7.5.0 | |
Vmware Vrealize Operations Manager | =8.0.0 | |
Vmware Vrealize Operations Manager | =8.0.1 | |
Vmware Vrealize Operations Manager | =8.1.0 | |
Vmware Vrealize Operations Manager | =8.1.1 | |
Vmware Vrealize Operations Manager | =8.2.0 | |
Vmware Vrealize Operations Manager | =8.3.0 | |
Vmware Vrealize Suite Lifecycle Manager | =8.0 | |
Vmware Vrealize Suite Lifecycle Manager | =8.0.1 | |
Vmware Vrealize Suite Lifecycle Manager | =8.1 | |
Vmware Vrealize Suite Lifecycle Manager | =8.2 | |
=3.0 | ||
=3.0.1 | ||
=3.0.1.1 | ||
=3.5 | ||
=3.5.1 | ||
=3.7 | ||
=3.7.1 | ||
=3.7.2 | ||
=3.8 | ||
=3.8.1 | ||
=3.9 | ||
=3.9.1 | ||
=3.10 | ||
=4.0 | ||
=4.0.1 | ||
=7.0.0 | ||
=7.5.0 | ||
=8.0.0 | ||
=8.0.1 | ||
=8.1.0 | ||
=8.1.1 | ||
=8.2.0 | ||
=8.3.0 | ||
=8.0 | ||
=8.0.1 | ||
=8.1 | ||
=8.2 | ||
VMware vRealize Operations Manager API |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.