← Back to browse · API

CVE-2021-21975

Severity
HIGH
CVSS
7.5
EPSS
0.7829
Risk score
82.4
CISA KEV
Yes
PoC
No
Published
2022-01-18
Modified
2022-01-18
First seen
2026-08-07
Aliases
EUVD-2021-9146, GHSA-PX27-325W-M34C
Products
VMware:vRealize Operations Manager API, n/a:VMware vRealize Operations VMware vRealize Operations prior to 8.4
Sources
euvd EUVD-2021-9146
cisa.gov CVE-2021-21975

Description

Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.

References