CVE-2021-22025: High severity vmware vcenter server and cloud foundation vulnerability
The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can add new nodes to existing vROps cluster.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2021-22025.
What is the severity rating of CVE-2021-22025?
The severity rating of CVE-2021-22025 is high with a severity value of 7.5.
What is the affected software?
The affected software includes VMware Cloud Foundation (versions 3.0 to 3.10.2.1), VMware vRealize Operations Manager (versions 8.0.0 to 8.5.0), and VMware vRealize Suite Lifecycle Manager (versions 8.0 to 8.2).
What is the description of CVE-2021-22025?
CVE-2021-22025 is a broken access control vulnerability in the vRealize Operations Manager API (8.x prior to 8.5) that allows unauthenticated API access and the ability to add new nodes to an existing vROps cluster.
Is there a fix available for CVE-2021-22025?
Yes, VMware has released a security advisory (VMSA-2021-0018) that includes a fix for CVE-2021-22025. It is recommended to apply the necessary patches or updates provided by VMware.