CVE-2021-21975

KEV
🔴 Łataj teraz

Atak Server Side Request Forgery w vRealize Operations Manager API pozwala na kradzież danych uwierzytelniających.

CVSS
7.5
EPSS
78.3%
Exploit
weaponized
Vendor
vmware
Opis źródłowy (NVD)

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.

exploit ssrf Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Tak
FIRST EPSS (prawdopodobieństwo exploita)78.3%
Opublikowano (NVD)2021-03-31 18:15:14 UTC
Ostatnia modyfikacja (NVD)2026-08-12 05:17:35 UTC
Referencje