ZeroHour
Security Affairspublished ()ingested @securityaffairs

VMware addresses SSRF flaw in vRealize Operations that allows stealing admin credentials

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-21975
SSRF in VMware vRealize Operations Manager API Enables Admin Credential Theft

CVE-2021-21975 is a server-side request forgery (CWE-918) in the vRealize Operations Manager API affecting versions prior to 8.4. A malicious actor with network access to the vRealize Operations Manager API endpoint can trigger the flaw without authentication or user interaction, causing the server to make attacker-influenced requests. Successful abuse lets the attacker steal administrative credentials for vRealize Operations Manager; a public proof-of-concept additionally demonstrates chaining the SSRF into code execution. Organizations running vRealize Operations Manager on-premises, including VMware Cloud Foundation and vRealize Suite Lifecycle Manager deployments that include it, are affected. The flaw is listed in CISA's Known Exploited Vulnerabilities Catalog (added 2022-01-18) with known ransomware use and carries a very high EPSS score of 78.3%, indicating active, widespread exploitation.

Do: Upgrade vRealize Operations Manager to version 8.4 or later (or apply the update in the bundled Cloud Foundation / vRealize Suite Lifecycle Manager releases per VMware's advisory instructions), as required by CISA's KEV listing. Restrict network access to the vRealize Operations Manager API to trusted management networks until patched, and review logs for signs of SSRF-driven requests or unauthorized use of stolen administrative credentials, given the known ransomware exploitation.

7.578% KEV ransomware PoC
  • vmware vrealize operations manager prior to 8.4
  • vmware cloud foundation deployments bundling vRealize Operations Manager prior to 8.4
  • vmware vrealize suite lifecycle manager deployments bundling vRealize Operations Manager prior to 8.4
largetens of thousands of enterprise deployments (thousands of instances exposed to the internet)
CVE-2021-21983
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network acce

Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.

NVD description · AI analysis pending
6.569% PoC
  • vmware cloud foundation
  • vmware vrealize operations manager
  • vmware vrealize suite lifecycle manager
Full article334 words · extracted from securityaffairs.com · click to collapse

VMware addressed a high severity vulnerability in vRealize Operations that could allow stealing admin credentials from vulnerable servers.

VMware has published security updates to address multiple vulnerabilities in VMware vRealize Operations that could allow threat actors to steal admin credentials from vulnerable installs.

VMware vRealize Operations is a self-driving and AI-powered platform for the management of IT operations for private, hybrid, and multi-cloud environments. The solution is available as an on-premises or SaaS solution.

The most severe vulnerability, tracked as CVE-2021-21975, is a Server Side Request Forgery in vRealize Operations Manager API, it received a CVSSv3 base score of 8.6.

“The vRealize Operations Manager API contains a Server Side Request Forgery. VMware has evaluated this issue to be of ‘Important’ severity with a maximum CVSSv3 base score of 8.6.” reads the advisory published by the virtualization giant.

“A malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.”

A remote, unauthenticated attacker can exploit the vulnerability without user interaction to steal administrative credentials.

The vulnerability was reported to VMware by security researcher Egor Dimitrenko from Positive Technologies.

The company also addressed an arbitrary file write vulnerability in vRealize Operations Manager API tracked as CVE-2021-21983 that received a CVSSv3 base score of 7.2.

“An authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.” reads the advisory published by the company. “To remediate CVE-2021-21983 apply the updates listed in the ‘Fixed Version’ column of the ‘Response Matrix’ below to affected deployments.”

Impacted products include:

  • VMware vRealize Operations
  • VMware Cloud Foundation
  • vRealize Suite Lifecycle Manager

VMware also announced the availability of workarounds for customers that can’t immediately install the security updates.

If you want to receive the weekly Security Affairs Newsletter for free subscribe here.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, SSRF)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/116145/security/vmware-vrealize-operations-ssrf-flaw.html