Skip to content
COOEY

EXPOSURES › CVE-2021-22054

CVE-2021-22054

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-03-09 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-22054 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatcheddata-breach

Omnissa Workspace ONE UEM suffered a server-side request forgery (SSRF) vulnerability allowing unauthenticated network access to sensitive data.

This SSRF flaw in Omnissa Workspace ONE UEM permits attackers with network access to bypass authentication and retrieve sensitive information, posing a significant risk to DIB organizations relying on this endpoint management solution. The vulnerability is actively exploited and requires immediate patching to prevent unauthorized data exfiltration and potential lateral movement within the network.

Shame score — While actively exploited, the vulnerability was disclosed and patched without lying about compliance or default credentials.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.