CVE-2021-21975
KEV ransomware PoC largeSSRF in VMware vRealize Operations Manager API Enables Admin Credential Theft
CISA: VMware Server Side Request Forgery in vRealize Operations Manager API
CVE-2021-21975 is a server-side request forgery (CWE-918) in the vRealize Operations Manager API affecting versions prior to 8.4. A malicious actor with network access to the vRealize Operations Manager API endpoint can trigger the flaw without authentication or user interaction, causing the server to make attacker-influenced requests. Successful abuse lets the attacker steal administrative credentials for vRealize Operations Manager; a public proof-of-concept additionally demonstrates chaining the SSRF into code execution. Organizations running vRealize Operations Manager on-premises, including VMware Cloud Foundation and vRealize Suite Lifecycle Manager deployments that include it, are affected. The flaw is listed in CISA's Known Exploited Vulnerabilities Catalog (added 2022-01-18) with known ransomware use and carries a very high EPSS score of 78.3%, indicating active, widespread exploitation.
What to do: Upgrade vRealize Operations Manager to version 8.4 or later (or apply the update in the bundled Cloud Foundation / vRealize Suite Lifecycle Manager releases per VMware's advisory instructions), as required by CISA's KEV listing. Restrict network access to the vRealize Operations Manager API to trusted management networks until patched, and review logs for signs of SSRF-driven requests or unauthorized use of stolen administrative credentials, given the known ransomware exploitation.
| vmware vrealize operations manager | prior to 8.4 |
| vmware cloud foundation | deployments bundling vRealize Operations Manager prior to 8.4 |
| vmware vrealize suite lifecycle manager | deployments bundling vRealize Operations Manager prior to 8.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
- Affected
- VMware vRealize Operations Manager API
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- vmware
- Products
- cloud foundation, vrealize operations manager, vrealize suite lifecycle manager
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N