CVE-2021-21975
VMware Server Side Request Forgery in vRealize Operations Manager API
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
6Exploited in Wild
YesDecision
Descriptions
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
una vulnerabilidad de Server Side Request Forgery en la API vRealize Operations Manager (CVE-2021-21975) anterior a la versiĆ³n 8.4, puede permitir que un actor malicioso con acceso de red a la API vRealize Operations Manager pueda realizar un ataque de tipo Server Side Request Forgery para robar credenciales administrativas.
Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-04 CVE Reserved
- 2021-03-31 CVE Published
- 2021-03-31 First Exploit
- 2022-01-18 Exploited in Wild
- 2022-02-01 KEV Due Date
- 2024-08-03 CVE Updated
- 2024-10-08 EPSS Updated
CWE
- CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
https://twitter.com/ptswarm/status/1376961747232382976 | ||
https://attackerkb.com/topics/51Vx3lNI7B/cve-2021-21975#rapid7-analysis |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.vmware.com/security/advisories/VMSA-2021-0004.html | 2021-03-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vmware Search vendor "Vmware" | Cloud Foundation Search vendor "Vmware" for product "Cloud Foundation" | 3.0 Search vendor "Vmware" for product "Cloud Foundation" and version "3.0" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Cloud Foundation Search vendor "Vmware" for product "Cloud Foundation" | 3.0.1 Search vendor "Vmware" for product "Cloud Foundation" and version "3.0.1" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Cloud Foundation Search vendor "Vmware" for product "Cloud Foundation" | 3.0.1.1 Search vendor "Vmware" for product "Cloud Foundation" and version "3.0.1.1" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Cloud Foundation Search vendor "Vmware" for product "Cloud Foundation" | 3.5 Search vendor "Vmware" for product "Cloud Foundation" and version "3.5" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Cloud Foundation Search vendor "Vmware" for product "Cloud Foundation" | 3.5.1 Search vendor "Vmware" for product "Cloud Foundation" and version "3.5.1" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Cloud Foundation Search vendor "Vmware" for product "Cloud Foundation" | 3.7 Search vendor "Vmware" for product "Cloud Foundation" and version "3.7" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Cloud Foundation Search vendor "Vmware" for product "Cloud Foundation" | 3.7.1 Search vendor "Vmware" for product "Cloud Foundation" and version "3.7.1" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Cloud Foundation Search vendor "Vmware" for product "Cloud Foundation" | 3.7.2 Search vendor "Vmware" for product "Cloud Foundation" and version "3.7.2" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Cloud Foundation Search vendor "Vmware" for product "Cloud Foundation" | 3.8 Search vendor "Vmware" for product "Cloud Foundation" and version "3.8" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Cloud Foundation Search vendor "Vmware" for product "Cloud Foundation" | 3.8.1 Search vendor "Vmware" for product "Cloud Foundation" and version "3.8.1" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Cloud Foundation Search vendor "Vmware" for product "Cloud Foundation" | 3.9 Search vendor "Vmware" for product "Cloud Foundation" and version "3.9" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Cloud Foundation Search vendor "Vmware" for product "Cloud Foundation" | 3.9.1 Search vendor "Vmware" for product "Cloud Foundation" and version "3.9.1" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Cloud Foundation Search vendor "Vmware" for product "Cloud Foundation" | 3.10 Search vendor "Vmware" for product "Cloud Foundation" and version "3.10" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Cloud Foundation Search vendor "Vmware" for product "Cloud Foundation" | 4.0 Search vendor "Vmware" for product "Cloud Foundation" and version "4.0" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Cloud Foundation Search vendor "Vmware" for product "Cloud Foundation" | 4.0.1 Search vendor "Vmware" for product "Cloud Foundation" and version "4.0.1" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Vrealize Operations Manager Search vendor "Vmware" for product "Vrealize Operations Manager" | 7.0.0 Search vendor "Vmware" for product "Vrealize Operations Manager" and version "7.0.0" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Vrealize Operations Manager Search vendor "Vmware" for product "Vrealize Operations Manager" | 7.5.0 Search vendor "Vmware" for product "Vrealize Operations Manager" and version "7.5.0" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Vrealize Operations Manager Search vendor "Vmware" for product "Vrealize Operations Manager" | 8.0.0 Search vendor "Vmware" for product "Vrealize Operations Manager" and version "8.0.0" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Vrealize Operations Manager Search vendor "Vmware" for product "Vrealize Operations Manager" | 8.0.1 Search vendor "Vmware" for product "Vrealize Operations Manager" and version "8.0.1" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Vrealize Operations Manager Search vendor "Vmware" for product "Vrealize Operations Manager" | 8.1.0 Search vendor "Vmware" for product "Vrealize Operations Manager" and version "8.1.0" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Vrealize Operations Manager Search vendor "Vmware" for product "Vrealize Operations Manager" | 8.1.1 Search vendor "Vmware" for product "Vrealize Operations Manager" and version "8.1.1" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Vrealize Operations Manager Search vendor "Vmware" for product "Vrealize Operations Manager" | 8.2.0 Search vendor "Vmware" for product "Vrealize Operations Manager" and version "8.2.0" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Vrealize Operations Manager Search vendor "Vmware" for product "Vrealize Operations Manager" | 8.3.0 Search vendor "Vmware" for product "Vrealize Operations Manager" and version "8.3.0" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Vrealize Suite Lifecycle Manager Search vendor "Vmware" for product "Vrealize Suite Lifecycle Manager" | 8.0 Search vendor "Vmware" for product "Vrealize Suite Lifecycle Manager" and version "8.0" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Vrealize Suite Lifecycle Manager Search vendor "Vmware" for product "Vrealize Suite Lifecycle Manager" | 8.0.1 Search vendor "Vmware" for product "Vrealize Suite Lifecycle Manager" and version "8.0.1" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Vrealize Suite Lifecycle Manager Search vendor "Vmware" for product "Vrealize Suite Lifecycle Manager" | 8.1 Search vendor "Vmware" for product "Vrealize Suite Lifecycle Manager" and version "8.1" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Vrealize Suite Lifecycle Manager Search vendor "Vmware" for product "Vrealize Suite Lifecycle Manager" | 8.2 Search vendor "Vmware" for product "Vrealize Suite Lifecycle Manager" and version "8.2" | - |
Affected
|