ZeroHour

CVE-2021-22023

CVSS 3.1
7.2 high
EPSS
<1%p61
Published
()
Modified
Description

The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to vRealize Operations Manager API may be able to modify other users information leading to an account takeover.

Vendors
vmware
Products
cloud foundation, vrealize operations manager, vrealize suite lifecycle manager
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news