Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Very High
CVE-2021-21983
Disclosure Date: March 31, 2021 (last updated November 28, 2024)
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.
0
Attacker Value
Unknown
CVE-2021-22033
Disclosure Date: October 13, 2021 (last updated November 28, 2024)
Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability.
0
Attacker Value
Unknown
CVE-2021-22027
Disclosure Date: August 30, 2021 (last updated November 28, 2024)
The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack leading to information disclosure.
0
Attacker Value
Unknown
CVE-2021-22024
Disclosure Date: August 30, 2021 (last updated November 28, 2024)
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read any log file resulting in sensitive information disclosure.
0
Attacker Value
Unknown
CVE-2021-22025
Disclosure Date: August 30, 2021 (last updated November 28, 2024)
The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can add new nodes to existing vROps cluster.
0
Attacker Value
Unknown
CVE-2021-22023
Disclosure Date: August 30, 2021 (last updated November 28, 2024)
The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to vRealize Operations Manager API may be able to modify other users information leading to an account takeover.
0
Attacker Value
Unknown
CVE-2021-22022
Disclosure Date: August 30, 2021 (last updated November 28, 2024)
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor with administrative access to vRealize Operations Manager API can read any arbitrary file on server leading to information disclosure.
0
Attacker Value
Unknown
CVE-2021-22026
Disclosure Date: August 30, 2021 (last updated November 28, 2024)
The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack leading to information disclosure.
0