Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2021-21975

VMware | vRealize Operations Manager APIAdded 2022-01-18Remediation Deadline 2022-02-01Active Ransomware Campaign

VMware Server Side Request Forgery in vRealize Operations Manager API

Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.

Required Action

Apply updates per vendor instructions.

Weakness Classification

CWE-918

References