Skip to content
COOEY

EXPOSURES › CVE-2021-21975

CVE-2021-21975

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-01-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-21975 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwareexploited-in-wildunpatched

VMware's vRealize Operations Manager API had a critical SSRF vulnerability exploited in the wild, potentially leading to credential theft and system compromise.

A SSRF vulnerability in vRealize Operations Manager API (prior to 8.4) allowed network-accessible attackers to steal administrative credentials, actively exploited and linked to ransomware. DIB organizations using this product must immediately patch and review network access controls to prevent unauthorized access and potential data exfiltration, impacting CMMC/NIST 800-171 compliance.

Shame score — The SSRF vulnerability, coupled with active exploitation and potential for credential theft, demonstrates a significant security oversight with serious operational consequences.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
VMware Government Services (VGS)
VMware, Inc.
Authorized
Workspace ONE
VMware, Inc.
Authorized