LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-21975: VMware Server Side Request Forgery in vRealize Operations Manager API

RBRecent Breaches Vulnerability Intelligence·Jan 18, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Feb 1, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-21975 to its Known Exploited Vulnerabilities catalog on Jan 18, 2022, with a federal patch deadline of Feb 1, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to…

CVE-2021-21975 is a server-side request forgery (SSRF) weakness in the VMware vRealize Operations Manager API. An attacker who can reach that API over the network may abuse it to steal administrative credentials. CISA notes known ransomware use, so organizations running this product should treat exposure as high priority and confirm all version and fix details against the vendor advisory.

The flaw affects the vRealize Operations Manager API prior to 8.4. Because the product is commonly used to monitor and manage virtual infrastructure, successful abuse can give an attacker a path to privileged credentials and broader environment access.

How it works

This vulnerability is classified as CWE-918 (Server-Side Request Forgery). In an SSRF flaw, the application accepts a request from a client and then makes a further request to a URL or internal resource chosen or influenced by that client, without adequate validation.

According to the CISA summary, a malicious actor with network access to the vRealize Operations Manager API can perform an SSRF attack that results in theft of administrative credentials. The attacker does not necessarily need prior authentication to the management plane; network reachability to the API is the stated prerequisite. Exact request parameters and internal targets are not detailed here and must be confirmed against the vendor advisory; defenders should assume the API can be induced to contact internal services or metadata endpoints that hold or can reveal privileged credentials.

Am I affected? How to find it in your systems

vRealize Operations Manager is typically deployed in VMware environments as a management and monitoring appliance or cluster, often reachable from administrative jump hosts, monitoring networks, or broader data-center segments. Inventory every instance of vRealize Operations Manager and identify whether its API endpoint is network-accessible.

How to remediate

Patch first. Apply the updates published by VMware for vRealize Operations Manager as directed in the vendor advisory and per CISA’s required action to apply updates per vendor instructions. Confirm that every instance has moved to a fixed release (the summary cites prior to 8.4 as affected; verify the exact fixed versions in the advisory).

If you can't patch immediately

Implement compensating controls until the vendor update can be applied.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, frequently lead to credential theft and follow-on breaches. If your vRealize Operations Manager API was reachable by untrusted networks while unpatched, assume administrative credentials may have been targeted and proceed with incident response: isolate affected systems, rotate credentials, and hunt for lateral movement. You can also run a free exposure scan of your email addresses to check whether associated accounts appear in known breach data sets and take further action on any confirmed exposures.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedVMware · vRealize Operations Manager API
WeaknessCWE-918
Added to CISA KEVJan 18, 2022
Federal patch deadlineFeb 1, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities