3a. Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975)
The vRealize Operations Manager API contains a Server Side Request Forgery. VMware has evaluated this issue to be of βImportantβ severity with a maximum CVSSv3 base score of 8.6.
3b. Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983)
The vRealize Operations Manager API contains an arbitrary file write vulnerability. VMware has evaluated this issue to be of βImportantβ severity with a maximum CVSSv3 base score of 7.2.
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21975
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21983
kb.vmware.com/s/article/82367
kb.vmware.com/s/article/83093
kb.vmware.com/s/article/83094
kb.vmware.com/s/article/83095
kb.vmware.com/s/article/83210
kb.vmware.com/s/article/83260
kb.vmware.com/s/article/83287
www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N