A AegiFlow
HIGHCVSS 7.5KNOWN EXPLOITEDRANSOMWARE: KNOWN

CVE-2021-21975

CVE-2021-21975 updated by NVD

Published
2022-01-18
Modified
2026-09-21
Sources
cisa-kev, nvd

Summary

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.