CVE-2021-21975
Last modified
CVE-2021-21975 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.. CISA has confirmed active exploitation in the wild. EPSS estimates a 78.29% chance of exploitation in the next 30 days.
Description
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Cloud Foundation | 3.0 |
| Vmware | Cloud Foundation | 3.0.1 |
| Vmware | Cloud Foundation | 3.0.1.1 |
| Vmware | Cloud Foundation | 3.5 |
| Vmware | Cloud Foundation | 3.5.1 |
| Vmware | Cloud Foundation | 3.7 |
| Vmware | Cloud Foundation | 3.7.1 |
| Vmware | Cloud Foundation | 3.7.2 |
| Vmware | Cloud Foundation | 3.8 |
| Vmware | Cloud Foundation | 3.8.1 |
| Vmware | Cloud Foundation | 3.9 |
| Vmware | Cloud Foundation | 3.9.1 |
| Vmware | Cloud Foundation | 3.10 |
| Vmware | Cloud Foundation | 4.0 |
| Vmware | Cloud Foundation | 4.0.1 |
| Vmware | Vrealize Operations Manager | 7.0.0 |
| Vmware | Vrealize Operations Manager | 7.5.0 |
| Vmware | Vrealize Operations Manager | 8.0.0 |
| Vmware | Vrealize Operations Manager | 8.0.1 |
| Vmware | Vrealize Operations Manager | 8.1.0 |
| Vmware | Vrealize Operations Manager | 8.1.1 |
| Vmware | Vrealize Operations Manager | 8.2.0 |
| Vmware | Vrealize Operations Manager | 8.3.0 |
| Vmware | Vrealize Suite Lifecycle Manager | 8.0 |
| Vmware | Vrealize Suite Lifecycle Manager | 8.0.1 |
| Vmware | Vrealize Suite Lifecycle Manager | 8.1 |
| Vmware | Vrealize Suite Lifecycle Manager | 8.2 |
References
- https://packetstormsecurity.com/files/162349/VMware-vRealize-Operations-Manager-Server-Side-Request-Forgery-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/162349/VMware-vRealize-Operations-Manager-Server-Side-Request-Forgery-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-21975US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2021-21975?
How severe is CVE-2021-21975?
How do I fix CVE-2021-21975?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-2197Vulnerability in the Oracle iStore product of Oracle E-Busin…8.2
- CVE-2021-21970An out-of-bounds write vulnerability exists in the HandleSea…8.1
- CVE-2021-21971An out-of-bounds write vulnerability exists in the URL_decod…5.9
- CVE-2021-21972The vSphere Client (HTML5) contains a remote code execution …9.8
- CVE-2021-21973The vSphere Client (HTML5) contains an SSRF (Server Side Req…5.3
- CVE-2021-21974OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 …8.8
- CVE-2021-21976vSphere Replication 8.3.x prior to 8.3.1.2, 8.2.x prior to 8…7.2
- CVE-2021-21978VMware View Planner 4.x prior to 4.6 Security Patch 1 contai…9.8
- CVE-2021-21979In Bitnami Containers, all Laravel container versions prior …7.3
- CVE-2021-2198Vulnerability in the Oracle Knowledge Management product of …8.2
- CVE-2021-21980The vSphere Web Client (FLEX/Flash) contains an unauthorized…7.5
- CVE-2021-21981VMware NSX-T contains a privilege escalation vulnerability d…7.8
Are you affected by CVE-2021-21975?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
