CVE-2021-21975
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
- Affected products
- Vrealize Operations
- Vmware Cloud Foundation
- = 3.0, 3.0.1, 3.0.1.1, 3.5, 3.5.1, 3.7, 3.7.1, 3.7.2, 3.8, 3.8.1, 3.9, 3.9.1, 3.10, 4.0, 4.0.1
- Vmware Vrealize Operations Manager
- = 7.0.0, 7.5.0, 8.0.0, 8.0.1, 8.1.0, 8.1.1, 8.2.0, 8.3.0
- Vmware Vrealize Suite Lifecycle Manager
- = 8.0, 8.0.1, 8.1, 8.2
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 78.3% (100th percentile)
- Weakness
- CWE-918
- NVD status
- Analyzed
- Published
- 2021-03-31
CVE-2021-21975 at NVD
20 known exploits for CVE-2021-21975
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2021-21975
CVE-2021-21975
REALITY_SMASHER
VMWare-CVE-2021-21975
VMWare-vRealize-SSRF
VmWare-vCenter-vulnerability
exp_hub
CVE-2021-21975
CVE-2021-21983
CVE-2021-21975
Exploit for CVE-2021-21983
VMware vRealize Operations Manager Server-Side Request Forgery / Code Execution Exploit
VMware vRealize Operations Manager Server-Side Request Forgery / Code Execution
Exploit for Server-Side Request Forgery in Vmware Cloud_Foundation
Exploit for Server-Side Request Forgery in Vmware Cloud_Foundation
Exploit for Server-Side Request Forgery in Vmware Cloud_Foundation
Exploit for Server-Side Request Forgery in Vmware Cloud_Foundation
Exploit for Server-Side Request Forgery in Vmware Cloud_Foundation
VMware vRealize Operations Manager SSRF和文件读取漏洞(CVE-2021-21975 CVE-2021-21983)
VMware vRealize Operations (vROps) Manager SSRF RCE