VMware patches critical vRealize Operations flaws that could lead to RCE
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-21975 | SSRF in VMware vRealize Operations Manager API Enables Admin Credential Theft CVE-2021-21975 is a server-side request forgery (CWE-918) in the vRealize Operations Manager API affecting versions prior to 8.4. A malicious actor with network access to the vRealize Operations Manager API endpoint can trigger the flaw without authentication or user interaction, causing the server to make attacker-influenced requests. Successful abuse lets the attacker steal administrative credentials for vRealize Operations Manager; a public proof-of-concept additionally demonstrates chaining the SSRF into code execution. Organizations running vRealize Operations Manager on-premises, including VMware Cloud Foundation and vRealize Suite Lifecycle Manager deployments that include it, are affected. The flaw is listed in CISA's Known Exploited Vulnerabilities Catalog (added 2022-01-18) with known ransomware use and carries a very high EPSS score of 78.3%, indicating active, widespread exploitation. Do: Upgrade vRealize Operations Manager to version 8.4 or later (or apply the update in the bundled Cloud Foundation / vRealize Suite Lifecycle Manager releases per VMware's advisory instructions), as required by CISA's KEV listing. Restrict network access to the vRealize Operations Manager API to trusted management networks until patched, and review logs for signs of SSRF-driven requests or unauthorized use of stolen administrative credentials, given the known ransomware exploitation. | 7.5 | 78% | KEV ransomware PoC |
| largetens of thousands of enterprise deployments (thousands of instances exposed to the internet) | |
| CVE-2021-21983 | Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network acce Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system. NVD description · AI analysis pending | 6.5 | 69% | PoC |
| — |
Full article247 words · extracted from helpnetsecurity.com · click to collapse
Two vulnerabilities (CVE-2021-21975, CVE-2021-21983) recently patched by VMware in its vRealize Operations platform can be chained together to achieve unauthenticated remote code execution (RCE) on the underlying operating system, Positive Technologies researchers have found.

There is no PoC currently available and no mention of the vulnerabilities being exploited in the wild. Nevertheless, administrators are advised to implement provided security patches or temporary workarounds as soon as possible.
VMware vRealize Operations vulnerabilities could lead to RCE
VMware vRealize Operations is a unified, AI-powered platform for IT operations management for private, hybrid, and multi-cloud environments. It is available on premises and as SaaS.
Both vulnerabilities are in the vRealize Operations Manager API.
CVE-2021-21975 is a Server Side Request Forgery (SSRF) flaw that could be exploited remotely by an unauthenticated attacker to steal administrative credentials, and CVE-2021-21983 is an arbitrary file write vulnerability that could allow an authenticated remote attacker to write files to arbitrary locations on the underlying operating system.
They have been deemed to be high-risk, but chained together they can lead to unauthenticated remote code execution.
The vulnerabilities are present in vRealize Operations Manager 7.5.0, 8.0.1, 8.0.0, 8.1.1, 8.1.0, 8.2.0, and 8.3.0, and also impact VMware Cloud Foundation versions 3.x and 4.x and vRealize Suite Lifecycle Manager v8.x.
Security updates
Security updates are available and so are workarounds, which don’t have an impact on the system’s functionality.
Security researcher Egor Dimitrenko of Positive Technologies has been credited with discovering and reporting the vulnerabilities to VMware.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2021/04/01/vmware-vrealize-operations-rce/