CVE-2021-22023: High severity vmware vcenter server and cloud foundation vulnerability
The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to vRealize Operations Manager API may be able to modify other users information leading to an account takeover.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-22023?
CVE-2021-22023 is a vulnerability in the vRealize Operations Manager API (8.x prior to 8.5) that allows a malicious actor with administrative access to modify other users' information and potentially take over their accounts.
How severe is CVE-2021-22023?
CVE-2021-22023 has a severity rating of 7.2 (high).
Which software versions are affected by CVE-2021-22023?
CVE-2021-22023 affects VMware Cloud Foundation versions 3.0 to 3.10.2.1, VMware vRealize Operations Manager versions 8.0.0 to 8.5.0, and VMware vRealize Suite Lifecycle Manager versions 8.0 to 8.2.
How can I fix CVE-2021-22023?
To fix CVE-2021-22023, it is recommended to upgrade to vRealize Operations Manager API version 8.5 or later.
Where can I find more information about CVE-2021-22023?
More information about CVE-2021-22023 can be found in the VMware security advisory VMSA-2021-0018 at https://www.vmware.com/security/advisories/VMSA-2021-0018.html.