Sploitus

CVE-2021-21975

20 known exploits for CVE-2021-21975

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.

Affected products
Vrealize Operations
Vmware Cloud Foundation
= 3.0, 3.0.1, 3.0.1.1, 3.5, 3.5.1, 3.7, 3.7.1, 3.7.2, 3.8, 3.8.1, 3.9, 3.9.1, 3.10, 4.0, 4.0.1
Vmware Vrealize Operations Manager
= 7.0.0, 7.5.0, 8.0.0, 8.0.1, 8.1.0, 8.1.1, 8.2.0, 8.3.0
Vmware Vrealize Suite Lifecycle Manager
= 8.0, 8.0.1, 8.1, 8.2
Fix
Available
CVSS 3.1
7.5 HIGH
EPSS
78.3% (100th percentile)
Weakness
CWE-918
NVD status
Analyzed
Published
2021-03-31
CVE-2021-21975 at NVD
Authoritative description, scoring and affected products

20 known exploits for CVE-2021-21975

Proof-of-concept code and exploit modules indexed by Sploitus