Vulnerability record · CVE-2021-21975 · published 31 March 2021
CVE-2021-21975: VMware vRealize Operations Manager API server-side request forgery
Vmware · Cloud Foundation
The vRealize Operations Manager API before 8.4 is vulnerable to server-side request forgery, allowing a remote unauthenticated attacker to make the server issue requests on their behalf. Because the flaw can be used to steal administrative credentials, it exposes the management plane of the affected products to full compromise.
Description
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityThe flaw is remotely exploitable without authentication, is in CISA KEV with known ransomware use, and has a very high EPSS score.
What it is
The vRealize Operations Manager API before 8.4 is vulnerable to server-side request forgery, allowing a remote unauthenticated attacker to make the server issue requests on their behalf. Because the flaw can be used to steal administrative credentials, it exposes the management plane of the affected products to full compromise.
Impact
An attacker can abuse the API to reach internal services and capture administrative credentials, which can then be used to take over vRealize Operations Manager and related management components.
Attack surface
The flaw is reachable over the network through the vRealize Operations Manager API; the CVSS vector shows no privileges or user interaction required, so any host that can reach the API can attempt it.
Exploitation
It is listed in CISA KEV with a due date of 2022-02-01 and flagged for known ransomware campaign use, and EPSS gives a 30-day probability of 0.7829 (99.556th percentile); public exploit code is referenced by Packet Storm.
What to do
- Apply the vendor update per VMware advisory VMSA-2021-0004 to move to vRealize Operations Manager 8.4 or later.
- Restrict network access to the vRealize Operations Manager API to trusted management networks only.
- Rotate administrative credentials for vRealize Operations Manager and connected products after patching.
- Monitor CISA KEV guidance and confirm remediation of the listed products (Cloud Foundation, vRealize Operations Manager, vRealize Suite Lifecycle Manager).
Detection
- Review vRealize Operations Manager API logs for unexpected outbound requests or requests to unusual internal hosts.
- Alert on authentication events using administrative accounts from unexpected source IPs.
- Hunt for outbound connections from the vRealize Operations Manager host to internal services that are not part of normal operation.
- Correlate API access logs with network flow data for SSRF-style request patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-21975 to the Known Exploited Vulnerabilities catalog on 18 January 2022 as "VMware Server Side Request Forgery in vRealize Operations Manager API". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 1 February 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/162349/VMware-vRealize-Operations-Manager-Server-Side-Request-Forgery-Code-Executio | ExploitThird Party AdvisoryVDB Entry |
| https://www.vmware.com/security/advisories/VMSA-2021-0004.html | Vendor Advisory |
| http://packetstormsecurity.com/files/162349/VMware-vRealize-Operations-Manager-Server-Side-Request-Forgery-Code-Executio | ExploitThird Party AdvisoryVDB Entry |
| https://www.vmware.com/security/advisories/VMSA-2021-0004.html | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-21975 | US Government Resource |
Track CVE-2021-21975 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-21975), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.