PT-2021-4132 · Vmware · Vrealize Operations Manager Api
Egor Dimitrenko
·
Published
2021-08-24
·
Updated
2022-02-01
·
CVE-2021-22022
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
vRealize Operations Manager API versions 8.x prior to 8.5
Description
The issue is related to an arbitrary file read vulnerability in the vRealize Operations Manager API. A malicious actor with administrative access can read any arbitrary file on the server, leading to information disclosure. The vulnerability is associated with insufficient validation of incoming requests.
Recommendations
For versions 8.x prior to 8.5, update to version 8.5 or later to resolve the issue. As a temporary workaround, consider restricting administrative access to the vRealize Operations Manager API to minimize the risk of exploitation.
Fix
Path traversal
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vrealize Operations Manager Api