CVE-2021-22054
KEVlargeUnauthenticated SSRF in VMware (Omnissa) Workspace ONE UEM Console
CISA: Omnissa Workspace ONE Server-Side Request Forgery
VMware (now Omnissa) Workspace ONE UEM console, in the 20.0.8, 20.11.0, 21.2.0 and 21.5.0 release lines before their fixed builds, contains a server-side request forgery flaw (CWE-918). A malicious actor with network access to the UEM console can trigger it by sending crafted, unauthenticated requests, causing the console to issue requests on the attacker's behalf. Successful exploitation can give the attacker access to sensitive information reachable from the console (high confidentiality impact, with no integrity or availability impact per the CVSS score). Organizations running an affected Workspace ONE UEM console deployment are exposed, with risk concentrated on consoles reachable from untrusted networks. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-03-09, EPSS assigns a 97.4% probability of exploitation within 30 days (100th percentile), and reporting describes a coordinated SSRF exploitation surge involving 400+ source IPs.
What to do: Upgrade the Workspace ONE UEM console to the fixed builds — 20.0.8.37, 20.11.0.40, 21.2.0.27, or 21.5.0.37 (or later). Until patched, restrict network access to the console (management networks/VPN only, no direct internet exposure) and review logs for unauthenticated or anomalous outbound requests from the console, especially given the reported coordinated SSRF exploitation wave from 400+ IPs. Organizations subject to federal BOD 22-01 must apply vendor mitigations or the prescribed cloud-service guidance.
| vmware (Omnissa) Workspace ONE UEM console | 20.0.8 prior to 20.0.8.37 |
| vmware (Omnissa) Workspace ONE UEM console | 20.11.0 prior to 20.11.0.40 |
| vmware (Omnissa) Workspace ONE UEM console | 21.2.0 prior to 21.2.0.27 |
| vmware (Omnissa) Workspace ONE UEM console | 21.5.0 prior to 21.5.0.37 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.
- Affected
- Omnissa Workspace One UEM
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- vmware
- Products
- workspace one uem console
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N