Lucene search

K
vmwareVMwareVMSA-2021-0004.2
HistoryMar 30, 2021 - 12:00 a.m.

VMware vRealize Operations updates address Server Side Request Forgery and Arbitrary File Write vulnerabilities (CVE-2021-21975, CVE-2021-21983)

2021-03-3000:00:00
www.vmware.com
24

7.1 High

AI Score

Confidence

High

0.974 High

EPSS

Percentile

99.9%

3a. Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975)

The vRealize Operations Manager API contains a Server Side Request Forgery. VMware has evaluated this issue to be of β€˜Important’ severity with a maximum CVSSv3 base score of 8.6.

3b. Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983)

The vRealize Operations Manager API contains an arbitrary file write vulnerability. VMware has evaluated this issue to be of β€˜Important’ severity with a maximum CVSSv3 base score of 7.2.