CVE-2021-21983: Medium severity VMware Cloud Foundation vulnerability
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-21983?
CVE-2021-21983 is an arbitrary file write vulnerability in vRealize Operations Manager API.
How does CVE-2021-21983 occur?
CVE-2021-21983 occurs when an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.
What is the severity of CVE-2021-21983?
CVE-2021-21983 has a severity rating of 6.5 (high).
Which software versions are affected by CVE-2021-21983?
VMware Cloud Foundation versions 3.0 to 4.0.1, VMware vRealize Operations Manager versions 7.0.0 to 8.3.0, and VMware vRealize Suite Lifecycle Manager versions 8.0 to 8.2 are affected by CVE-2021-21983.
How do I fix CVE-2021-21983?
To fix CVE-2021-21983, it is recommended to upgrade to the patched versions provided by VMware.