HIGH

CVE-2021-21975

Vmware Cloud Foundation 2021-03-31 CVSS v3.1
CVSS
7.5
KEV

Description

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.

Summary dbcve.org

CVE-2021-21975 is a Server Side Request Forgery (SSRF) vulnerability in the vRealize Operations Manager API affecting versions prior to 8.4. An attacker with network access to the API can craft malicious requests that cause the server to make unintended outbound requests to internal or external resources, enabling theft of administrative credentials.

Mitigation

Upgrade vRealize Operations Manager to version 8.4 or later to remediate this vulnerability. As a compensating control, restrict network access to the API to trusted sources and implement network segmentation to limit the impact of potential SSRF exploitation.

Proof of Concept

Weakness (CWE)

CWE-918 Server-Side Request Forgery (SSRF)

EPSS Score

78.29%
Probability of exploitation in next 30 days
99.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE