CVE-2021-21983
⚪ Do wiadomości
Luka w API vRealize Operations Manager pozwala na zapis plików w dowolnych lokalizacjach systemu.
CVSS
6.5
EPSS
68.6%
Exploit
poc
Vendor
vmware
Opis źródłowy (NVD)
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 68.6% |
| Opublikowano (NVD) | 2021-03-31 18:15:14 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-12 05:17:36 UTC |
Referencje
- http://packetstormsecurity.com/files/162349/VMware-vRealize-Operations-Manager-Server-Side-Request-Forgery-Code-Execution.html (security@vmware.com) [Exploit, Third Party Advisory, VDB Entry]
- https://www.vmware.com/security/advisories/VMSA-2021-0004.html (security@vmware.com) [Vendor Advisory]