First published: Wed Mar 31 2021(Updated: )
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
Credit: security@vmware.com security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vRealize Operations Manager API | ||
VMware vCenter Server and Cloud Foundation | =3.0 | |
VMware vCenter Server and Cloud Foundation | =3.0.1 | |
VMware vCenter Server and Cloud Foundation | =3.0.1.1 | |
VMware vCenter Server and Cloud Foundation | =3.5 | |
VMware vCenter Server and Cloud Foundation | =3.5.1 | |
VMware vCenter Server and Cloud Foundation | =3.7 | |
VMware vCenter Server and Cloud Foundation | =3.7.1 | |
VMware vCenter Server and Cloud Foundation | =3.7.2 | |
VMware vCenter Server and Cloud Foundation | =3.8 | |
VMware vCenter Server and Cloud Foundation | =3.8.1 | |
VMware vCenter Server and Cloud Foundation | =3.9 | |
VMware vCenter Server and Cloud Foundation | =3.9.1 | |
VMware vCenter Server and Cloud Foundation | =3.10 | |
VMware vCenter Server and Cloud Foundation | =4.0 | |
VMware vCenter Server and Cloud Foundation | =4.0.1 | |
VMware vRealize Operations | =7.0.0 | |
VMware vRealize Operations | =7.5.0 | |
VMware vRealize Operations | =8.0.0 | |
VMware vRealize Operations | =8.0.1 | |
VMware vRealize Operations | =8.1.0 | |
VMware vRealize Operations | =8.1.1 | |
VMware vRealize Operations | =8.2.0 | |
VMware vRealize Operations | =8.3.0 | |
VMware vRealize Suite Lifecycle Manager | =8.0 | |
VMware vRealize Suite Lifecycle Manager | =8.0.1 | |
VMware vRealize Suite Lifecycle Manager | =8.1 | |
VMware vRealize Suite Lifecycle Manager | =8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21975 has a CVSS v3 base score of 6.5, indicating a medium severity vulnerability.
To fix CVE-2021-21975, update VMware vRealize Operations Manager API to version 8.4 or later.
Due to CVE-2021-21975, a server-side request forgery (SSRF) attack can be executed, potentially allowing unauthorized access to administrative credentials.
CVE-2021-21975 affects VMware vRealize Operations Manager API and various versions of VMware Cloud Foundation.
A malicious actor with network access to the vRealize Operations Manager API can exploit CVE-2021-21975.