CVE-2021-22023
- EPSS 0.32%
- Veröffentlicht 30.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:27
The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to vRealize Operations Manager API may be able to modify other users information leading to an account ta...
CVE-2021-22024
- EPSS 0.27%
- Veröffentlicht 30.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:27
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read any log file resulting in sensitive infor...
CVE-2021-22025
- EPSS 0.19%
- Veröffentlicht 30.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:27
The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can add new nod...
CVE-2021-22026
- EPSS 0.25%
- Veröffentlicht 30.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:27
The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery att...
CVE-2021-22027
- EPSS 0.23%
- Veröffentlicht 30.08.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:27
The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery att...
CVE-2021-21994
- EPSS 0.38%
- Veröffentlicht 13.07.2021 19:15:09
- Zuletzt bearbeitet 31.10.2025 11:44:38
SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a specially crafted request.
CVE-2021-21995
- EPSS 0.47%
- Veröffentlicht 13.07.2021 19:15:09
- Zuletzt bearbeitet 31.10.2025 11:44:38
OpenSLP as used in ESXi has a denial-of-service vulnerability due a heap out-of-bounds read issue. A malicious actor with network access to port 427 on ESXi may be able to trigger a heap out-of-bounds read in OpenSLP service resulting in a denial-of-...
- EPSS 94.41%
- Veröffentlicht 26.05.2021 15:15:07
- Zuletzt bearbeitet 30.10.2025 20:05:29
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exp...
- EPSS 1.49%
- Veröffentlicht 26.05.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 05:49:22
The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-ins. A malicious actor with network acce...
CVE-2021-21975
- EPSS 94.42%
- Veröffentlicht 31.03.2021 18:15:14
- Zuletzt bearbeitet 30.10.2025 20:06:02
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrati...