ZeroHour

CVE-2021-21983

PoC
CVSS 3.1
6.5 medium
EPSS
69%p99
Published
()
Modified
Description

Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.

Vendors
vmware
Products
cloud foundation, vrealize operations manager, vrealize suite lifecycle manager
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

In the news