vulnti.work

VMware Server Side Request Forgery in vRealize Operations Manager API

High CVSS 7.5 Listed in CISA KEV
CVECVE-2021-21975
First seen2022-01-18 00:00 UTC
Disclosed2021-03-31 18:15 UTC
Last updated2026-09-04 02:01 UTC
Channel statuspending_review

Summary

Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.

In-depth triage · Auto channel

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Affected products

  • VMware:vRealize Operations Manager API
  • :

Sources

  • CISA KEV DATABASE
  • NVD DATABASE

Original Links

Timeline

  1. kev_added CISA KEV
  2. kev_ingest CISA KEV
  3. nvd_ingest NVD