CVE-2021-21975
VMware vRealize Operations Manager API
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
- CVSS
- 7.5
- EPSS
- 78.3% 99.5% percentile
- CISA KEV
- Listed
- Published
- 2021.04.01