{"cveID":"CVE-2021-21975","vendorProject":"VMware","product":"vRealize Operations Manager API","vulnerabilityName":"VMware Server Side Request Forgery in vRealize Operations Manager API","dateAdded":"2022-01-18","shortDescription":"Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-02-01","knownRansomwareCampaignUse":"Known","notes":"https://nvd.nist.gov/vuln/detail/CVE-2021-21975","cwes":["CWE-918"],"year":2021,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2021-21975","technique":"T1190","technique_name_at_mapping":"Exploit Public-Facing Application","mapping_type":"exploitation_technique","capability_group":"ssrf","comments":"This Server-Side Request Forgery (SSRF) vulnerability is exploited by an attacker with network access to the VMware server. This vulnerability enables the attacker to exploit an unauthenticated endpoint to send crafted requests to internal or external systems. By doing so, the attacker can potentially steal administrative credentials. Once these credentials are compromised, the attacker could gain maximum privileges within the application, enabling them to alter configurations and intercept sensitive data. This exploitation could lead to unauthorized access and manipulation of the application.","references":["https://attackerkb.com/topics/51Vx3lNI7B/cve-2021-21975/rapid7-analysis","https://www.darkreading.com/vulnerabilities-threats/vmware-fixes-dangerous-vulnerabilities-in-software-for-infrastructure-monitoring"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1190","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploit Public-Facing Application","name_at_mapping":"Exploit Public-Facing Application","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":149,"has_detection_strategy":true}],"mapping_types":["exploitation_technique"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}