VMware fixes critical SSRF flaw in Workspace ONE UEM Console
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-22054 | Unauthenticated SSRF in VMware (Omnissa) Workspace ONE UEM Console VMware (now Omnissa) Workspace ONE UEM console, in the 20.0.8, 20.11.0, 21.2.0 and 21.5.0 release lines before their fixed builds, contains a server-side request forgery flaw (CWE-918). A malicious actor with network access to the UEM console can trigger it by sending crafted, unauthenticated requests, causing the console to issue requests on the attacker's behalf. Successful exploitation can give the attacker access to sensitive information reachable from the console (high confidentiality impact, with no integrity or availability impact per the CVSS score). Organizations running an affected Workspace ONE UEM console deployment are exposed, with risk concentrated on consoles reachable from untrusted networks. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-03-09, EPSS assigns a 97.4% probability of exploitation within 30 days (100th percentile), and reporting describes a coordinated SSRF exploitation surge involving 400+ source IPs. Do: Upgrade the Workspace ONE UEM console to the fixed builds — 20.0.8.37, 20.11.0.40, 21.2.0.27, or 21.5.0.37 (or later). Until patched, restrict network access to the console (management networks/VPN only, no direct internet exposure) and review logs for unauthenticated or anomalous outbound requests from the console, especially given the reported coordinated SSRF exploitation wave from 400+ IPs. Organizations subject to federal BOD 22-01 must apply vendor mitigations or the prescribed cloud-service guidance. | 7.5 | 97% | KEV |
| largeon the order of tens of thousands of on-premises UEM console deployments (estimate) |
Full article400 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
December 17, 2021

VMware released security patches for a critical server-side request forgery (SSRF) vulnerability in Workspace ONE UEM console.
VMware has addressed a critical server-side request forgery (SSRF) vulnerability, tracked as CVE-2021-22054, in the Workspace ONE UEM console.
An attacker with network access to UEM could exploit the vulnerability to access sensitive data in the management console. An attacker can trigger the issue by sending unauthenticated requests to the vulnerable software.
“VMware Workspace ONE UEM console contains a Server Side Request Forgery (SSRF) vulnerability. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.1.” reads the analysis published by VMware. “A malicious actor with network access to UEM can send their requests without authentication and may exploit this issue to gain access to sensitive information.”
Below is the list of impacted versions:
| Impacted Versions | Fixed Version |
|---|---|
| 2109 | Workspace ONE UEM patch 21.9.0.13 and above |
| 2105 | Workspace ONE UEM patch 21.5.0.37 and above |
| 2102 | Workspace ONE UEM patch 21.2.0.27 and above |
| 2101 | Workspace ONE UEM patch 21.1.0.27 and above |
| 2011 | Workspace ONE UEM patch 20.11.0.40 and above |
| 2010 | Workspace ONE UEM patch 20.10.0.23 and above |
| 2008 | Workspace ONE UEM patch 20.8.0.36 and above |
| 2007 | Workspace ONE UEM patch 20.7.0.17 and above |
The virtualization giant has rated the issue as Critical and assigned it a CVSSv3 base score of 9.1. The SSRF vulnerability in Workspace ONE UEM console was privately reported to the company which released security patches and workarounds.
The company fixed the issue with the release of VMware Workspace ONE UEM console versions 21.5.0.37, 21.2.0.27, 20.11.0.40, and 20.0.8.36. VMware Workspace ONE UEM patch 21.9.0.13 and above also fixed the vulnerability.
The company also shared the following required actions in guidance for addressing CVE-2021-22054 (87167).
Shared and Dedicated SaaS: None. The issue has been mitigated across all SaaS environments through infrastructure changes which will remain in place until VMware Cloud Operations has deployed the necessary patches. Please subscribe to this article to be notified when updates are available
On-premise: Deploy the patch associated with the supported version of Workspace ONE UEM that your environment is on. Alternatively, you may implement the short-term mitigation noted below
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, VMware Workspace ONE UEM)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/125736/security/vmware-ssrf-workspace-one-uem-console.html