CVE-2021-21975

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the...

Basic Information

CVE State
PUBLISHED
Reserved Date
January 04, 2021
Published Date
March 31, 2021
Last Updated
January 29, 2025
Vendor
n/a
Product
VMware vRealize Operations
Description
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
Tags
cisa malware ransomware nuclei_scanner metasploit_scanner

CVSS Scores

CVSS v3.1

7.5 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v2.0

5.0

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
partial

Exploit Status

Exploited in the Wild
Yes (2022-01-18 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2021-03-31 13:33:45 UTC) Source
Used in Malware
Yes (added 2022-01-18 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2022-01-18 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

Vulnmachines/VMWare-CVE-2021-21975

Type: github • Created: 2021-04-10 12:36:07 UTC • Stars: 3

VMWare-CVE-2021-21975 SSRF vulnerability

murataydemir/CVE-2021-21975

Type: github • Created: 2021-04-02 21:14:06 UTC • Stars: 4

[CVE-2021-21975] VMware vRealize Operations Manager API Server Side Request Forgery (SSRF)

GuayoyoCyber/CVE-2021-21975

Type: github • Created: 2021-04-01 21:59:05 UTC • Stars: 28

Nmap script to check vulnerability CVE-2021-21975

Al1ex/CVE-2021-21975

Type: github • Created: 2021-03-31 15:40:09 UTC • Stars: 13

CVE-2021-21975 vRealize Operations Manager SSRF

dorkerdevil/CVE-2021-21975

Type: github • Created: 2021-03-31 13:33:45 UTC • Stars: 2

Timeline

  • CVE ID Reserved

  • Proof of Concept Exploit Available

  • CVE Published to Public

  • Exploit Used in Malware

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit