Server Side Request Forgery Vulnerability in VMware vRealize Operations Manager
CVE-2021-22027
7.5HIGH
What is CVE-2021-22027?
The vRealize Operations Manager API prior to version 8.5 is susceptible to a Server Side Request Forgery (SSRF) vulnerability. This issue allows an unauthenticated attacker with network access to exploit the endpoint, potentially leading to unauthorized information disclosure. The vulnerability poses a risk as attackers may manipulate requests sent to the internal systems, which could expose sensitive data or facilitate further attacks within the network.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
VMware vRealize Operations VMware vRealize Operations (8.x prior to 8.5)
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved