CVE-2021-21975VMware Server Side Request Forgery in vRealize Operations Manager API

PUBLISHEDvulnerability record
2022-01-18 · last modified June 21, 2025

Metadata

CVE ID:
CVE-2021-21975
Project:
VMware
Product:
vRealize Operations Manager API
Date Added:
2022-01-18
Due Date:
2022-02-01
Last Updated:
June 21, 2025

Vulnerability Name

VMware Server Side Request Forgery in vRealize Operations Manager API

Description

Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.

Known To Be Used in Ransomware Campaigns?

Ransomware Status:
KNOWN

Action

Apply updates per vendor instructions.

Additional Notes

Related Weaknesses