CVE-2021-22054 - Omnissa Workspace ONE Server-Side Request Forgery
Project:Omnissa
Product:Workspace One UEM
Date Added:2026-03-09Due Date:2026-03-23
Vulnerability Name
Omnissa Workspace ONE Server-Side Request Forgery
Description
Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://web.archive.org/web/20211222154335/https://www.vmware.com/security/advisories/VMSA-2021-0029.html
https://nvd.nist.gov/vuln/detail/CVE-2021-22054
Related News Articles
CISA Flags SolarWinds, Ivanti, and Workspace One Vulnerabilities as Actively ExploitedMarch 10, 2026