Vulnerability Description
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
Affected Platforms (CPE)
π¦
Cloud Foundation
= 3.0π¦
Cloud Foundation
= 3.0.1π¦
Cloud Foundation
= 3.0.1.1π¦
Cloud Foundation
= 3.5π¦
Cloud Foundation
= 3.5.1π¦
Cloud Foundation
= 3.7π¦
Cloud Foundation
= 3.7.1π¦
Cloud Foundation
= 3.7.2π¦
Cloud Foundation
= 3.8π¦
Cloud Foundation
= 3.8.1π¦
Cloud Foundation
= 3.9π¦
Cloud Foundation
= 3.9.1π¦
Cloud Foundation
= 3.10π¦
Cloud Foundation
= 4.0π¦
Cloud Foundation
= 4.0.1π¦
Vrealize Operations Manager
= 7.0.0π¦
Vrealize Operations Manager
= 7.5.0π¦
Vrealize Operations Manager
= 8.0.0π¦
Vrealize Operations Manager
= 8.0.1π¦
Vrealize Operations Manager
= 8.1.0π¦
Vrealize Operations Manager
= 8.1.1π¦
Vrealize Operations Manager
= 8.2.0π¦
Vrealize Operations Manager
= 8.3.0π¦
Vrealize Suite Lifecycle Manager
= 8.0π¦
Vrealize Suite Lifecycle Manager
= 8.0.1π¦
Vrealize Suite Lifecycle Manager
= 8.1π¦
Vrealize Suite Lifecycle Manager
= 8.2