claytonvantol.us
SESSION: secure TLS: 1.3 PID: 1337

clayton@site:~/news$ cat cve-2021-21975-vmware-vrealize-operations-manager-api.log

CVE-2021-21975 — VMware Server Side Request Forgery in vRealize Operations Manager API

2022-01-18 • CISA Known Exploited Vulnerability


[event] Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.

> AFFECTED SOFTWARE

Field Value
Vendor VMware
Product vRealize Operations Manager API
CWE CWE-918
CVE ID CVE-2021-21975
Date Added 2022-01-18
Due Date 2022-02-01
Ransomware Campaign Known — this vulnerability has been leveraged in ransomware campaigns

> MITIGATION

Apply updates per vendor instructions.

Due Date: 2022-02-01

> REFERENCES


← back to terminal

UPTIME: 1337d v2.0.1 privacy LAST LOGIN: 2026-05-30 20:36:14 UTC