CVE-2021-21975
Description
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
Summary dbcve.org
CVE-2021-21975 is a Server Side Request Forgery (SSRF) vulnerability in the vRealize Operations Manager API affecting versions prior to 8.4. An attacker with network access to the API can craft malicious requests that cause the server to make unintended outbound requests to internal or external resources, enabling theft of administrative credentials.
Mitigation
Upgrade vRealize Operations Manager to version 8.4 or later to remediate this vulnerability. As a compensating control, restrict network access to the API to trusted sources and implement network segmentation to limit the impact of potential SSRF exploitation.