CVE-2021-21983

Scores

EPSS

0.832high83.2%
0%20%40%60%80%100%

Percentile: 83.2%

CVSS

6.5medium3.x
0246810

CVSS Score: 6.5/10

All CVSS Scores

CVSS 3.x
6.5

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

CVSS 2.0
8.5

Vector: AV:N/AC:L/Au:S/C:N/I:C/A:C

Description

Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

Related Vulnerabilities

Exploits

Exploit ID: CVE-2021-21983

Source: github-poc

URL: https://github.com/murataydemir/CVE-2021-21983

Vulnerable Software (3)

Type: Configuration

Vendor: *

Product: cloud_foundation

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:vmware:cloud_foundation:3.0:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:vmware:cloud_foundation:3.0.1:*:*:*...

Source: nvd

Type: Configuration

Vendor: *

Product: vrealize_operations_manager

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:vmware:cloud_foundation:3.0:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:vmware:cloud_foundation:3.0.1:*:*:*...

Source: nvd

Type: Configuration

Vendor: *

Product: vrealize_suite_lifecycle_manager

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:vmware:cloud_foundation:3.0:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:vmware:cloud_foundation:3.0.1:*:*:*...

Source: nvd

End of list