Skip to main content

vRealize Operations Manager API vulnerabilities

1 published alerts for VMware vRealize Operations Manager API.

Actively exploited (KEV)Ransomware

CVE-2021-21975

VMware Server Side Request Forgery in vRealize Operations Manager API vulnerability

VMware vRealize Operations Manager API is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-21975). Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials. CISA remediation due date: 2022-02-01. If you need help checking exposure, call (864) 335-9223.