{"id":"CVE-2021-21975","title":"Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal…","summary":"Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-918","CWE-918"],"vendor":"vmware","product":"cloud_foundation","affected":["cloud_foundation = 3.0","cloud_foundation = 3.0.1","cloud_foundation = 3.0.1.1","cloud_foundation = 3.5","cloud_foundation = 3.5.1","cloud_foundation = 3.7","cloud_foundation = 3.7.1","cloud_foundation = 3.7.2","cloud_foundation = 3.8","cloud_foundation = 3.8.1","cloud_foundation = 3.9","cloud_foundation = 3.9.1","cloud_foundation = 3.10","cloud_foundation = 4.0","cloud_foundation = 4.0.1","vrealize_operations_manager = 7.0.0","vrealize_operations_manager = 7.5.0","vrealize_operations_manager = 8.0.0","vrealize_operations_manager = 8.0.1","vrealize_operations_manager = 8.1.0","vrealize_operations_manager = 8.1.1","vrealize_operations_manager = 8.2.0","vrealize_operations_manager = 8.3.0","vrealize_suite_lifecycle_manager = 8.0","vrealize_suite_lifecycle_manager = 8.0.1","vrealize_suite_lifecycle_manager = 8.1","vrealize_suite_lifecycle_manager = 8.2"],"published":"2021-03-31","updated":"2026-08-12","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-21975","references":[{"url":"http://packetstormsecurity.com/files/162349/VMware-vRealize-Operations-Manager-Server-Side-Request-Forgery-Code-Execution.html","label":"security@vmware.com"},{"url":"https://www.vmware.com/security/advisories/VMSA-2021-0004.html","label":"security@vmware.com"},{"url":"http://packetstormsecurity.com/files/162349/VMware-vRealize-Operations-Manager-Server-Side-Request-Forgery-Code-Execution.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.vmware.com/security/advisories/VMSA-2021-0004.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-21975","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.7829,"epssPercentile":0.99572,"kev":true,"kevDateAdded":"2022-01-18","kevDueDate":"2022-02-01","kevRansomware":true,"exploited":true,"ingestedAt":"2026-08-12T19:54:25.814Z","exploits":{"github":8,"githubRepos":["https://github.com/Henry4E36/VMWare-vRealize-SSRF","https://github.com/dorkerdevil/CVE-2021-21975","https://github.com/Al1ex/CVE-2021-21975"],"metasploit":["exploit/linux/http/vmware_vrops_mgr_ssrf_rce"],"nuclei":["CVE-2021-21975"],"checkedAt":"2026-09-21T15:24:09.814Z"},"exploitAvailable":true,"slug":"CVE-2021-21975","body":"## Overview\n\nServer Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.\n\n## Affected\n\n- `cloud_foundation = 3.0`\n- `cloud_foundation = 3.0.1`\n- `cloud_foundation = 3.0.1.1`\n- `cloud_foundation = 3.5`\n- `cloud_foundation = 3.5.1`\n- `cloud_foundation = 3.7`\n- `cloud_foundation = 3.7.1`\n- `cloud_foundation = 3.7.2`\n- `cloud_foundation = 3.8`\n- `cloud_foundation = 3.8.1`\n- `cloud_foundation = 3.9`\n- `cloud_foundation = 3.9.1`\n- `cloud_foundation = 3.10`\n- `cloud_foundation = 4.0`\n- `cloud_foundation = 4.0.1`\n- `vrealize_operations_manager = 7.0.0`\n- `vrealize_operations_manager = 7.5.0`\n- `vrealize_operations_manager = 8.0.0`\n- `vrealize_operations_manager = 8.0.1`\n- `vrealize_operations_manager = 8.1.0`\n- `vrealize_operations_manager = 8.1.1`\n- `vrealize_operations_manager = 8.2.0`\n- `vrealize_operations_manager = 8.3.0`\n- `vrealize_suite_lifecycle_manager = 8.0`\n- `vrealize_suite_lifecycle_manager = 8.0.1`\n- `vrealize_suite_lifecycle_manager = 8.1`\n- `vrealize_suite_lifecycle_manager = 8.2`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":87,"depthScoreParts":{"impact":41.3,"likelihood":15.7,"exploitation":25,"ransomware":5},"changes":[{"seq":4502,"id":"CVE-2021-21975","ts":1788887186023,"field":"exploit_available","old":"false","new":"true"},{"seq":3385,"id":"CVE-2021-21975","ts":1788886303746,"field":"exploit_available","old":"true","new":"false"},{"seq":2240,"id":"CVE-2021-21975","ts":1788882973375,"field":"exploit_available","old":"false","new":"true"},{"seq":1269,"id":"CVE-2021-21975","ts":1788882385036,"field":"exploit_available","old":"true","new":"false"},{"seq":383,"id":"CVE-2021-21975","ts":1788881820373,"field":"exploit_available","old":"false","new":"true"}]}