CVE-2021-21975—VMware Server Side Request Forgery in vRealize Operations Manager API
PUBLISHEDvulnerability record
2022-01-18 · last modified June 21, 2025
Metadata
Vulnerability Name
VMware Server Side Request Forgery in vRealize Operations Manager API
Description
Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.
Known To Be Used in Ransomware Campaigns?
Action
Apply updates per vendor instructions.