EXPOSURES › CVE-2021-21975
CVE-2021-21975
CRITICAL ⌖ ON CISA KEV · EXPLOITEDVMware's vRealize Operations Manager API had a critical SSRF vulnerability exploited in the wild, potentially leading to credential theft and system compromise.
A SSRF vulnerability in vRealize Operations Manager API (prior to 8.4) allowed network-accessible attackers to steal administrative credentials, actively exploited and linked to ransomware. DIB organizations using this product must immediately patch and review network access controls to prevent unauthorized access and potential data exfiltration, impacting CMMC/NIST 800-171 compliance.
Shame score — The SSRF vulnerability, coupled with active exploitation and potential for credential theft, demonstrates a significant security oversight with serious operational consequences.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.
| PRODUCT | STATUS |
|---|---|
| VMware Government Services (VGS) VMware, Inc. |
Authorized |
| Workspace ONE VMware, Inc. |
Authorized |