First published: Wed Mar 31 2021(Updated: )
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
Credit: security@vmware.com security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vRealize Operations Manager API | ||
VMware Cloud Foundation | =3.0 | |
VMware Cloud Foundation | =3.0.1 | |
VMware Cloud Foundation | =3.0.1.1 | |
VMware Cloud Foundation | =3.5 | |
VMware Cloud Foundation | =3.5.1 | |
VMware Cloud Foundation | =3.7 | |
VMware Cloud Foundation | =3.7.1 | |
VMware Cloud Foundation | =3.7.2 | |
VMware Cloud Foundation | =3.8 | |
VMware Cloud Foundation | =3.8.1 | |
VMware Cloud Foundation | =3.9 | |
VMware Cloud Foundation | =3.9.1 | |
VMware Cloud Foundation | =3.10 | |
VMware Cloud Foundation | =4.0 | |
VMware Cloud Foundation | =4.0.1 | |
VMware vRealize Operations | =7.0.0 | |
VMware vRealize Operations | =7.5.0 | |
VMware vRealize Operations | =8.0.0 | |
VMware vRealize Operations | =8.0.1 | |
VMware vRealize Operations | =8.1.0 | |
VMware vRealize Operations | =8.1.1 | |
VMware vRealize Operations | =8.2.0 | |
VMware vRealize Operations | =8.3.0 | |
VMware vRealize Suite Lifecycle Manager | =8.0 | |
VMware vRealize Suite Lifecycle Manager | =8.0.1 | |
VMware vRealize Suite Lifecycle Manager | =8.1 | |
VMware vRealize Suite Lifecycle Manager | =8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.