← CVE Tracker
7.5HIGHCISA KEV — actively exploited

CVE-2021-21975 — Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a…

Vmware · Cloud Foundation · Published 31 Mar 2021 · Modified 2 Oct 2026

Description

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.

References

What to do
  1. Check whether Cloud Foundation is in your asset inventory.
  2. Exploitation confirmed — patch within 72 hours.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2021-21975