CVE-2021-21975: VMware Server Side Request Forgery in vRealize Operations Manager API
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
Other sources
Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21975?
CVE-2021-21975 has a CVSS v3 base score of 6.5, indicating a medium severity vulnerability.
How do I fix CVE-2021-21975?
To fix CVE-2021-21975, update VMware vRealize Operations Manager API to version 8.4 or later.
What type of attack can occur due to CVE-2021-21975?
Due to CVE-2021-21975, a server-side request forgery (SSRF) attack can be executed, potentially allowing unauthorized access to administrative credentials.
Which products are affected by CVE-2021-21975?
CVE-2021-21975 affects VMware vRealize Operations Manager API and various versions of VMware Cloud Foundation.
Who can exploit CVE-2021-21975?
A malicious actor with network access to the vRealize Operations Manager API can exploit CVE-2021-21975.