S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2021-21975 Scanner

Detects 'Server-Side-Request-Forgery (SSRF)' vulnerability in vRealize Operations Manager API affects v. prior to 8.4.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
6.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-21975
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
VMware vRealize Operationsby n/a
VMware vRealize Operations prior to 8.4
Updated Sep 14, 2026View on NVD →
Detail

vRealize Operations Manager is an operations management and monitoring tool that helps IT teams manage and monitor their virtual and physical infrastructure. The vRealize Operations Manager API is used by developers and administrators to automate tasks, retrieve performance data, and integrate with other tools. It provides a RESTful API, which allows users to interact with the vRealize Operations Manager system programmatically.

One of the vulnerabilities detected in vRealize Operations Manager API is CVE-2021-21975, which affects versions prior to 8.4. This vulnerability allows a malicious actor with network access to the vRealize Operations Manager API to perform a Server Side Request Forgery (SSRF) attack. SSRF attacks are particularly dangerous since the attacker can use internal network services to read and modify data or execute arbitrary code on the target server.

When exploited, this vulnerability can lead to the theft of administrative credentials. This could allow the attacker to gain full control over the vRealize Operations Manager system, potentially leading to data breaches, theft of intellectual property, and other malicious activities. Moreover, the attacker could pivot to other systems on the network, creating a chain of vulnerabilities that can be difficult to detect and remediate.

At s4e.io, we provide a powerful platform that helps organizations identify, prioritize, and remediate vulnerabilities in their digital assets. Our advanced features, such as automated vulnerability scanning and threat intelligence, enable organizations to stay ahead of emerging threats like CVE-2021-21975. Sign up for a demo today and see how we can help you secure your digital assets.

 

REFERENCES

Solution Advice

To prevent this vulnerability, users and administrators of vRealize Operations Manager API should take the following precautions:

  • Upgrade to the latest version of vRealize Operations Manager (version 8.4 or newer).
  • Restrict network access to the vRealize Operations Manager API to trusted sources only.
  • Use strong authentication and authorization methods to control access to the API.
  • Monitor logs and network traffic for suspicious activity.
  • Follow security best practices and apply patches as soon as they become available.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.