CVE-2021-21983
בינונית 6.5
תיאור (מקור, אנגלית)
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.
מדדים
- CVSS 3.1
-
6.5 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H - EPSS — סבירות ניצול
- 69% (אחוזון 100) נכון ל-8/10/2026
מוצרים מושפעים
vmware: cloud foundation; vmware: vrealize operations manager; vmware: vrealize suite lifecycle manager
קישורים
- https://www.vmware.com/security/advisories/VMSA-2021-0004.html Vendor Advisory
- https://www.vmware.com/security/advisories/VMSA-2021-0004.html Vendor Advisory
- http://packetstormsecurity.com/files/162349/VMware-vRealize-Operations-Manager… ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/162349/VMware-vRealize-Operations-Manager… ExploitThird Party AdvisoryVDB Entry