CVE-2021-22033: SSRF
Published Oct 13, 2021
·Updated
Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability.
Affected Software
3 affected components
VMware Cloud Foundation>=3.0.0<=4.3.1
VMware vRealize Operations>=7.0.0<8.6.0
VMware Vrealize Suite Lifecycle Manager>=8.0<=8.2
Remediation
Event History
Oct 13, 2021
CVE Published
via MITRE·03:42 PM
Data Sourced
via MITRE·03:42 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-22033.
2
What is the severity of CVE-2021-22033?
The severity of CVE-2021-22033 is medium.
3
Which software versions are affected by CVE-2021-22033?
Releases prior to VMware vRealize Operations 8.6, VMware Cloud Foundation 3.0.0 to 4.3.1, and VMware vRealize Suite Lifecycle Manager 8.0 to 8.2 are affected by CVE-2021-22033.
4
What is the description of CVE-2021-22033?
CVE-2021-22033 is a Server Side Request Forgery (SSRF) vulnerability in releases prior to VMware vRealize Operations 8.6.
5
Where can I find more information about CVE-2021-22033?
More information about CVE-2021-22033 can be found at https://www.vmware.com/security/advisories/VMSA-2021-0021.html.