PT-2021-6848 · Vmware · Vmware Workspace One Uem Console
Published
2021-12-16
·
Updated
2026-03-10
·
CVE-2021-22054
CVSS v2.0
9.4
9.4
High
| Base vector | Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
VMware Workspace ONE UEM versions 20.0.8 through 20.0.8.37
VMware Workspace ONE UEM versions 20.11.0 through 20.11.0.40
VMware Workspace ONE UEM versions 21.2.0 through 21.2.0.27
VMware Workspace ONE UEM versions 21.5.0 through 21.5.0.37
Description
VMware Workspace ONE UEM contains a Server-Side Request Forgery (SSRF) issue. This allows a malicious actor with network access to UEM to send requests without authentication and potentially gain access to sensitive information. The issue stems from insufficient validation of incoming requests. An unauthenticated attacker can make arbitrary HTTP requests.
Recommendations
Update VMware Workspace ONE UEM to version 20.0.8.37 or later.
Update VMware Workspace ONE UEM to version 20.11.0.40 or later.
Update VMware Workspace ONE UEM to version 21.2.0.27 or later.
Update VMware Workspace ONE UEM to version 21.5.0.37 or later.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
BDU:2022-02319
CVE-2021-22054
Affected Products
Vmware Workspace One Uem Console
References · 28
- 🔥 https://github.com/MKSx/CVE-2021-22054⭐ 4 · Exploit
- https://nvd.nist.gov/vuln/detail/CVE-2021-22054 · Security Note
- https://vmware.com/security/advisories/VMSA-2021-0029.html · Vendor Advisory
- https://web.archive.org/web/20211222154335/https://vmware.com/security/advisories/VMSA-2021-0029.html · Security Note
- https://bdu.fstec.ru/vul/2022-02319 · Security Note
- https://reddit.com/r/TechNadu/comments/1rpxcby/solarwinds_and_ivanti_under_fire_again_cisa_flags · Reddit Post
- https://reddit.com/r/pwnhub/comments/1rpgfqj/cisa_adds_three_significant_vulnerabilities_to · Reddit Post
- https://reddit.com/r/CVEWatch/comments/1rpsubj/top_10_trending_cves_10032026 · Reddit Post
- https://cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22054 · Note
- https://greynoise.io/blog/new-ssrf-exploitation-surge · Note
- https://twitter.com/threatcluster/status/2031286586030084495 · Twitter Post
- https://twitter.com/projectzerosum/status/2031302883149492471 · Twitter Post
- https://cybersecurity-help.cz/vdb/SB2021121701 · Note
- https://t.me/true_secator/6843 · Telegram Post
- https://twitter.com/dailycve/status/2031117494748934221 · Twitter Post