CyberSec.Space Logo
返回 CVE 浏览器

CVE-2021-21975

🔥 Known Exploited (CISA KEV)HIGH
7.5
CVSS Severity Score
EPSS Score62.4190%
EPSS Percentile96.89th
Published2021-03-31
Last Modified2025-10-30
Data SourcesNVDCISA KEVFIRST.org EPSS

Vulnerability Description

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.

Affected Platforms (CPE)

📦
Vmware

Cloud Foundation

= 3.0= 3.0.1= 3.0.1.1= 3.5= 3.5.1= 3.7= 3.7.1= 3.7.2= 3.8= 3.8.1= 3.9= 3.9.1= 3.10= 4.0= 4.0.1
📦
Vmware

Vrealize Operations Manager

= 7.0.0= 7.5.0= 8.0.0= 8.0.1= 8.1.0= 8.1.1= 8.2.0= 8.3.0
📦
Vmware

Vrealize Suite Lifecycle Manager

= 8.0= 8.0.1= 8.1= 8.2

References & Advisories

相關資安分析文章

相关漏洞威胁