{"id":"CVE-2021-21983","title":"Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locati…","summary":"Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locati…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H","vendor":"vmware","product":"cloud_foundation","affected":["cloud_foundation = 3.0","cloud_foundation = 3.0.1","cloud_foundation = 3.0.1.1","cloud_foundation = 3.5","cloud_foundation = 3.5.1","cloud_foundation = 3.7","cloud_foundation = 3.7.1","cloud_foundation = 3.7.2","cloud_foundation = 3.8","cloud_foundation = 3.8.1","cloud_foundation = 3.9","cloud_foundation = 3.9.1","cloud_foundation = 3.10","cloud_foundation = 4.0","cloud_foundation = 4.0.1","vrealize_operations_manager = 7.0.0","vrealize_operations_manager = 7.5.0","vrealize_operations_manager = 8.0.0","vrealize_operations_manager = 8.0.1","vrealize_operations_manager = 8.1.0","vrealize_operations_manager = 8.1.1","vrealize_operations_manager = 8.2.0","vrealize_operations_manager = 8.3.0","vrealize_suite_lifecycle_manager = 8.0","vrealize_suite_lifecycle_manager = 8.0.1","vrealize_suite_lifecycle_manager = 8.1","vrealize_suite_lifecycle_manager = 8.2"],"published":"2021-03-31","updated":"2026-08-12","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-21983","references":[{"url":"http://packetstormsecurity.com/files/162349/VMware-vRealize-Operations-Manager-Server-Side-Request-Forgery-Code-Execution.html","label":"security@vmware.com"},{"url":"https://www.vmware.com/security/advisories/VMSA-2021-0004.html","label":"security@vmware.com"},{"url":"http://packetstormsecurity.com/files/162349/VMware-vRealize-Operations-Manager-Server-Side-Request-Forgery-Code-Execution.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.vmware.com/security/advisories/VMSA-2021-0004.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.68557,"epssPercentile":0.99328,"ingestedAt":"2026-08-12T19:54:25.849Z","exploits":{"github":1,"githubRepos":["https://github.com/murataydemir/CVE-2021-21983"],"metasploit":["exploit/linux/http/vmware_vrops_mgr_ssrf_rce"],"checkedAt":"2026-09-21T15:24:09.852Z"},"exploitAvailable":true,"slug":"CVE-2021-21983","body":"## Overview\n\nArbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.\n\n## Affected\n\n- `cloud_foundation = 3.0`\n- `cloud_foundation = 3.0.1`\n- `cloud_foundation = 3.0.1.1`\n- `cloud_foundation = 3.5`\n- `cloud_foundation = 3.5.1`\n- `cloud_foundation = 3.7`\n- `cloud_foundation = 3.7.1`\n- `cloud_foundation = 3.7.2`\n- `cloud_foundation = 3.8`\n- `cloud_foundation = 3.8.1`\n- `cloud_foundation = 3.9`\n- `cloud_foundation = 3.9.1`\n- `cloud_foundation = 3.10`\n- `cloud_foundation = 4.0`\n- `cloud_foundation = 4.0.1`\n- `vrealize_operations_manager = 7.0.0`\n- `vrealize_operations_manager = 7.5.0`\n- `vrealize_operations_manager = 8.0.0`\n- `vrealize_operations_manager = 8.0.1`\n- `vrealize_operations_manager = 8.1.0`\n- `vrealize_operations_manager = 8.1.1`\n- `vrealize_operations_manager = 8.2.0`\n- `vrealize_operations_manager = 8.3.0`\n- `vrealize_suite_lifecycle_manager = 8.0`\n- `vrealize_suite_lifecycle_manager = 8.0.1`\n- `vrealize_suite_lifecycle_manager = 8.1`\n- `vrealize_suite_lifecycle_manager = 8.2`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":61,"depthScoreParts":{"impact":35.8,"likelihood":13.7,"exploitation":12,"ransomware":0},"changes":[{"seq":4503,"id":"CVE-2021-21983","ts":1788887186028,"field":"exploit_available","old":"false","new":"true"},{"seq":3386,"id":"CVE-2021-21983","ts":1788886303751,"field":"exploit_available","old":"true","new":"false"},{"seq":2241,"id":"CVE-2021-21983","ts":1788882973380,"field":"exploit_available","old":"false","new":"true"},{"seq":1270,"id":"CVE-2021-21983","ts":1788882385041,"field":"exploit_available","old":"true","new":"false"},{"seq":384,"id":"CVE-2021-21983","ts":1788881820380,"field":"exploit_available","old":"false","new":"true"}]}