Vulnerability Description
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
Affected Platforms (CPE)
📦
Cloud Foundation
= 3.0.1.1📦
Vrealize Operations Manager
= 7.0.0📦
Vrealize Operations Manager
= 7.5.0📦
Vrealize Operations Manager
= 8.0.0📦
Vrealize Operations Manager
= 8.0.1📦
Vrealize Operations Manager
= 8.1.0📦
Vrealize Operations Manager
= 8.1.1📦
Vrealize Operations Manager
= 8.2.0📦
Vrealize Operations Manager
= 8.3.0📦
Vrealize Suite Lifecycle Manager
= 8.0📦
Vrealize Suite Lifecycle Manager
= 8.0.1📦
Vrealize Suite Lifecycle Manager
= 8.1📦
Vrealize Suite Lifecycle Manager
= 8.2