CVE-2021-22024: High severity vmware vcenter server and cloud foundation vulnerability
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read any log file resulting in sensitive information disclosure.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-22024.
What is the severity of CVE-2021-22024?
The severity of CVE-2021-22024 is high with a severity value of 7.5.
What is affected by CVE-2021-22024?
The vRealize Operations Manager API (8.x prior to 8.5) is affected by CVE-2021-22024.
How can an attacker exploit CVE-2021-22024?
An unauthenticated malicious actor with network access to the vRealize Operations Manager API can exploit CVE-2021-22024 by reading any log file, resulting in sensitive information disclosure.
Is there a fix for CVE-2021-22024?
Yes, VMware has released a security advisory with remediation steps for CVE-2021-22024. Please refer to the official VMware security advisory for more details.