CVE-2021-21983
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 68.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
- EPSS
- 68.56% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- vmware/cloud foundation · vmware/vrealize operations manager · vmware/vrealize suite lifecycle manager
- Source
- security@vmware.com
References
- http://packetstormsecurity.com/files/162349/VMware-vRealize-Operations-Manager-Server-Side-Request-Forgery-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://www.vmware.com/security/advisories/VMSA-2021-0004.htmlVendor Advisory
- http://packetstormsecurity.com/files/162349/VMware-vRealize-Operations-Manager-Server-Side-Request-Forgery-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://www.vmware.com/security/advisories/VMSA-2021-0004.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.