Low
Share this page on social media
Sign up for Security Advisories
A SSRF vulnerability in VMware vRealize Operations was privately reported to VMware. Patches are available to address this vulnerability in impacted VMware products.
Description
vRealize Operations contains a Server Side Request Forgery (SSRF) vulnerability. VMware has evaluated the severity of this issue to be in the Low severity range with a maximum CVSSv3 base score of 2.7.
Known Attack Vectors
A malicious actor with administrative access to vRealize Operations can enumerate internal IPs and internal ports.
Resolution
To remediate CVE-2021-22033 apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found below.
Workarounds
None.
Additional Documentation
None.
Acknowledgements
VMware would like to thank AxisX for reporting this vulnerability to us.
Notes
None.
Response Matrix:
Product | Version | Running On | CVE Identifier | CVSSv3 | Severity | Fixed Version | Workarounds | Additional Documentation |
vRealize Operations
|
8.x, 7.x
|
Any
|
CVE-2021-22033
|
2.7
|
low
|
None
|
None
|
Impacted Product Suites that Deploy Response Matrix Components:
Product | Version | Running On | CVE Identifier | CVSSv3 | Severity | Fixed Version | Workarounds | Additional Documentation |
VMware Cloud Foundation (vROps)
|
4.x, 3.x
|
Any
|
CVE-2021-22033
|
2.7
|
low
|
Patch Pending
|
None
|
None
|
vRealize Suite Lifecycle Manager (vROps)
|
8.x
|
Any
|
CVE-2021-22033
|
2.7
|
low
|
Patch Pending
|
None
|
None
|
Remediation and Workarounds:
vRealize Operations
8.6.0: https://docs.vmware.com/en/vRealize-Operations/8.6/rn/vrealize-operations-86-release-notes/index.html
FIRST CVSSv3 Calculator:
CVE-2021-22033: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N (2.7)
Mitre CVE Dictionary Links:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22033
2021-10-12: VMSA-2021-0021
Initial security advisory.
E-mail list for product security notifications and announcements:
https://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce
This Security Advisory is posted to the following lists:
security-announce@lists.vmware.com
E-mail: security@vmware.com
PGP key at:
VMware Security Advisories
https://www.vmware.com/security/advisories
VMware Security Response Policy
https://www.vmware.com/support/policies/security_response.html
VMware Lifecycle Support Phases
https://www.vmware.com/support/policies/lifecycle.html
VMware Security & Compliance Blog
https://blogs.vmware.com/security
Copyright 2021 VMware Inc. All rights reserved.