First published: Wed Mar 31 2021(Updated: )
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Cloud Foundation | =3.0 | |
VMware Cloud Foundation | =3.0.1 | |
VMware Cloud Foundation | =3.0.1.1 | |
VMware Cloud Foundation | =3.5 | |
VMware Cloud Foundation | =3.5.1 | |
VMware Cloud Foundation | =3.7 | |
VMware Cloud Foundation | =3.7.1 | |
VMware Cloud Foundation | =3.7.2 | |
VMware Cloud Foundation | =3.8 | |
VMware Cloud Foundation | =3.8.1 | |
VMware Cloud Foundation | =3.9 | |
VMware Cloud Foundation | =3.9.1 | |
VMware Cloud Foundation | =3.10 | |
VMware Cloud Foundation | =4.0 | |
VMware Cloud Foundation | =4.0.1 | |
Vmware Vrealize Operations Manager | =7.0.0 | |
Vmware Vrealize Operations Manager | =7.5.0 | |
Vmware Vrealize Operations Manager | =8.0.0 | |
Vmware Vrealize Operations Manager | =8.0.1 | |
Vmware Vrealize Operations Manager | =8.1.0 | |
Vmware Vrealize Operations Manager | =8.1.1 | |
Vmware Vrealize Operations Manager | =8.2.0 | |
Vmware Vrealize Operations Manager | =8.3.0 | |
Vmware Vrealize Suite Lifecycle Manager | =8.0 | |
Vmware Vrealize Suite Lifecycle Manager | =8.0.1 | |
Vmware Vrealize Suite Lifecycle Manager | =8.1 | |
Vmware Vrealize Suite Lifecycle Manager | =8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21983 is an arbitrary file write vulnerability in vRealize Operations Manager API.
CVE-2021-21983 occurs when an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.
CVE-2021-21983 has a severity rating of 6.5 (high).
VMware Cloud Foundation versions 3.0 to 4.0.1, VMware vRealize Operations Manager versions 7.0.0 to 8.3.0, and VMware vRealize Suite Lifecycle Manager versions 8.0 to 8.2 are affected by CVE-2021-21983.
To fix CVE-2021-21983, it is recommended to upgrade to the patched versions provided by VMware.