This page lists publicly disclosed CVE vulnerabilities affecting vmware vrealize_operations_manager (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2021-22027 | The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack leading to information disclosure. | [email protected] | 7.5 | 0.23% | 2021-08-30 | 2024-11-21 |
| CVE-2021-22026 | The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack leading to information disclosure. | [email protected] | 7.5 | 0.30% | 2021-08-30 | 2024-11-21 |
| CVE-2021-22025 | The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can add new nodes to existing vROps cluster. | [email protected] | 7.5 | 0.19% | 2021-08-30 | 2024-11-21 |
| CVE-2021-22024 | The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read any log file resulting in sensitive information disclosure. | [email protected] | 7.5 | 0.32% | 2021-08-30 | 2024-11-21 |
| CVE-2021-22023 | The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to vRealize Operations Manager API may be able to modify other users information leading to an account takeover. | [email protected] | 7.2 | 0.32% | 2021-08-30 | 2024-11-21 |
| CVE-2021-22022 | The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor with administrative access to vRealize Operations Manager API can read any arbitrary file on server leading to information disclosure. | [email protected] | 4.9 | 0.21% | 2021-08-30 | 2024-11-21 |
| CVE-2021-21983 | Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system. | [email protected] | 6.5 | 83.18% | 2021-03-31 | 2024-11-21 |
| CVE-2021-21975 KEV | Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials. | [email protected] | 7.5 | 94.42% | 2021-03-31 | 2025-10-30 |