← Vulnerability feed

Vulnerability record · CVE-2021-21975 · published 31 March 2021

CVE-2021-21975: VMware vRealize Operations Manager API server-side request forgery

Vmware · Cloud Foundation

The vRealize Operations Manager API before 8.4 is vulnerable to server-side request forgery, allowing a remote unauthenticated attacker to make the server issue requests on their behalf. Because the flaw can be used to steal administrative credentials, it exposes the management plane of the affected products to full compromise.

7.5 CVSS 3.1 High CISA KEV since 18 Jan 2022 Known ransomware use EPSS 78% · top 0.4% CWE-918 · Server-side request forgery (SSRF)
7.5CVSS 3.1 base score, v2 5.0
78%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
5References, 2 tagged exploit
12 Aug 2026Last modified by NVD

Description

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw is remotely exploitable without authentication, is in CISA KEV with known ransomware use, and has a very high EPSS score.

What it is

The vRealize Operations Manager API before 8.4 is vulnerable to server-side request forgery, allowing a remote unauthenticated attacker to make the server issue requests on their behalf. Because the flaw can be used to steal administrative credentials, it exposes the management plane of the affected products to full compromise.

Impact

An attacker can abuse the API to reach internal services and capture administrative credentials, which can then be used to take over vRealize Operations Manager and related management components.

Attack surface

The flaw is reachable over the network through the vRealize Operations Manager API; the CVSS vector shows no privileges or user interaction required, so any host that can reach the API can attempt it.

Exploitation

It is listed in CISA KEV with a due date of 2022-02-01 and flagged for known ransomware campaign use, and EPSS gives a 30-day probability of 0.7829 (99.556th percentile); public exploit code is referenced by Packet Storm.

What to do

  • Apply the vendor update per VMware advisory VMSA-2021-0004 to move to vRealize Operations Manager 8.4 or later.
  • Restrict network access to the vRealize Operations Manager API to trusted management networks only.
  • Rotate administrative credentials for vRealize Operations Manager and connected products after patching.
  • Monitor CISA KEV guidance and confirm remediation of the listed products (Cloud Foundation, vRealize Operations Manager, vRealize Suite Lifecycle Manager).

Detection

  • Review vRealize Operations Manager API logs for unexpected outbound requests or requests to unusual internal hosts.
  • Alert on authentication events using administrative accounts from unexpected source IPs.
  • Hunt for outbound connections from the vRealize Operations Manager host to internal services that are not part of normal operation.
  • Correlate API access logs with network flow data for SSRF-style request patterns.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-21975 to the Known Exploited Vulnerabilities catalog on 18 January 2022 as "VMware Server Side Request Forgery in vRealize Operations Manager API". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 1 February 2022.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21975 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-38813VMware vCenter Server privilege escalation to root via crafted packetvCenter Server contains a privilege escalation flaw where a malicious actor with network access can send a specially crafted network packet to escala…KEVEPSS 17%analysed9.8CVE-2024-38812VMware vCenter Server DCERPC heap overflow allows remote code executionvCenter Server contains a heap-based buffer overflow (CWE-122/CWE-787) in its DCERPC protocol implementation. A remote, unauthenticated attacker can …KEVEPSS 55%analysed9.8CVE-2024-37079VMware vCenter Server DCERPC heap overflow allows remote code executionvCenter Server contains a heap-overflow (out-of-bounds write) in its DCERPC protocol implementation. A remote, unauthenticated attacker can send a cr…KEVEPSS 22%analysed9.8CVE-2022-22954VMware Workspace ONE Access and Identity Manager server-side template injection RCEVMware Workspace ONE Access and Identity Manager are affected by a server-side template injection flaw that allows remote code execution. A network-r…KEVEPSS 100%analysed9.8CVE-2021-22005VMware vCenter Server Analytics arbitrary file upload to RCEThe Analytics service in VMware vCenter Server accepts a specially crafted file upload, which the product mishandles as a path traversal issue (CWE-2…KEVEPSS 100%analysed9.8CVE-2021-21985VMware vCenter Server Virtual SAN Health Check plug-in RCEThe vSphere Client (HTML5) in vCenter Server fails to validate input in the Virtual SAN Health Check plug-in, which is enabled by default. This allow…KEVEPSS 100%analysed9.8CVE-2021-21972VMware vCenter Server plugin path traversal leads to remote code executionThe vSphere Client (HTML5) in vCenter Server contains a path traversal flaw (CWE-22) in a plugin that allows an unauthenticated network attacker to u…KEVEPSS 100%analysed9.8CVE-2020-3992VMware ESXi OpenSLP use-after-free allows remote code executionOpenSLP as used in VMware ESXi contains a use-after-free flaw reachable over port 427 on the management network. An unauthenticated attacker with net…KEVEPSS 83%analysed

Source: NIST National Vulnerability Database (record CVE-2021-21975), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.