PT-2021-6848 · Vmware · Vmware Workspace One Uem Console

CVE-2021-22054

·

Published

2021-12-16

·

Updated

2026-06-11

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions VMware Workspace ONE UEM versions 20.0.8 through 20.0.8.37 VMware Workspace ONE UEM versions 20.11.0 through 20.11.0.40 VMware Workspace ONE UEM versions 21.2.0 through 21.2.0.27 VMware Workspace ONE UEM versions 21.5.0 through 21.5.0.37
Description VMware Workspace ONE UEM contains a Server-Side Request Forgery (SSRF) issue. This allows a malicious actor with network access to UEM to send requests without authentication and potentially gain access to sensitive information. The issue stems from insufficient validation of incoming requests. An unauthenticated attacker can make arbitrary HTTP requests.
Recommendations Update VMware Workspace ONE UEM to version 20.0.8.37 or later. Update VMware Workspace ONE UEM to version 20.11.0.40 or later. Update VMware Workspace ONE UEM to version 21.2.0.27 or later. Update VMware Workspace ONE UEM to version 21.5.0.37 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02319
CVE-2021-22054

Affected Products

Vmware Workspace One Uem Console