CVE-2021-22022: Path Traversal
Published Aug 30, 2021
·Updated
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor with administrative access to vRealize Operations Manager API can read any arbitrary file on server leading to information disclosure.
Affected Software
5 affected components
VMware Cloud Foundation>=3.0<=3.10.2.1
VMware Cloud Foundation>=4.0<=4.2.1
VMware vRealize Operations Manager>=8.0.0<8.5.0
VMware vRealize Operations Manager=7.5.0
VMware Vrealize Suite Lifecycle Manager>=8.0<=8.2
Remediation
Event History
Aug 30, 2021
CVE Published
via MITRE·05:53 PM
Data Sourced
via MITRE·05:53 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-22022.
2
What is the severity of CVE-2021-22022?
The severity of CVE-2021-22022 is medium.
3
What is the affected software?
The affected software includes VMware Cloud Foundation, VMware vRealize Operations Manager, and VMware vRealize Suite Lifecycle Manager.
4
How can a malicious actor exploit CVE-2021-22022?
A malicious actor with administrative access to vRealize Operations Manager API can read any arbitrary file on the server.
5
Is there a fix available for CVE-2021-22022?
Yes, VMware has released a patch to address the vulnerability. Please refer to the VMware Security Advisory VMSA-2021-0018 for more information.