CVE-2021-21983
published 2021-03-31CVE-2021-21983: Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network…
PriorityP276medium6.5CVSS 3.1
AVNACLPRHUINSUCNIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
68.56%
99.3th percentile
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | vrealize_operations_manager | — | — |
| vmware | vrealize_operations_manager | — | — |
| vmware | vrealize_operations_manager | — | — |
| vmware | vrealize_operations_manager | — | — |
| vmware | vrealize_operations_manager | — | — |
| vmware | vrealize_operations_manager | — | — |
| vmware | vrealize_operations_manager | — | — |
| vmware | vrealize_operations_manager | — | — |
| vmware | vrealize_suite_lifecycle_manager | — | — |
| vmware | vrealize_suite_lifecycle_manager | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandPOST /casa/nodes/thumbprints HTTP/1.1
Host: {{Hostname}}
Content-Type: application/json;charset=UTF-8
["127.0.0.1:443/ui/"]↗
- →Detect exploitation of CVE-2021-21983 by monitoring POST requests to the /casa/private/config/slice/ha/certificate endpoint, which is the arbitrary file write vector requiring authentication (or chained with CVE-2021-21975 SSRF to bypass auth). ↗
- →Detect CVE-2021-21975 SSRF exploitation (used to chain into CVE-2021-21983) by monitoring POST requests to /casa/nodes/thumbprints with internal/loopback IP addresses in the JSON body (e.g., 127.0.0.1). ↗
- →Alert on response bodies from /casa/nodes/thumbprints containing 'vRealize Operations Manager', 'thumbprint', and 'address' simultaneously, which indicates successful SSRF exploitation leaking admin credentials. ↗
- →The Metasploit module exploits the chain to write and execute a JSP payload on the underlying Photon OS as the 'admin' Unix user; monitor for unexpected JSP file creation and execution on vROps hosts. ↗
- ·Version 8.3.0 is not exploitable for credential leakage via CVE-2021-21975 and is therefore not supported by the Metasploit chained RCE module, even though it is still vulnerable to CVE-2021-21983 in isolation. ↗
- ·CVE-2021-21983 requires authentication on its own; the unauthenticated RCE scenario only applies when chained with the CVE-2021-21975 SSRF to steal admin credentials first. ↗
- ·The workaround (modifying casa-security-context.xml and restarting the CaSA service) is explicitly temporary and should not replace patching. ↗
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
nvdv2.08.5HIGHAV:N/AC:L/Au:S/C:N/I:C/A:C
vulncheck6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4vwx-r658-c2mg: Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8
ghsa_unreviewed·2022-05-24·CVSS 6.5
CVE-2021-21983 [MEDIUM] GHSA-4vwx-r658-c2mg: Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.
VulnCheck
vRealize Operations Manager API prior to 8.4 Unauthenticated File Write
vulncheck·2021·CVSS 6.5
CVE-2021-21983 [MEDIUM] vRealize Operations Manager API prior to 8.4 Unauthenticated File Write
vRealize Operations Manager API prior to 8.4 Unauthenticated File Write
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.
Affected: VMware cloud_foundation
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://vblocalhost.com/uploads/VB2021-50.pdf
Exploit PoC: https://vulncheck.com/xdb/1c647bbacade
VMware
VMware vRealize Operations updates address Server Side Request Forgery and Arbitrary File Write vulnerabilities (CVE-2021-21975, CVE-2021-21983)
vendor_vmware·2021-03-30·CVSS 7.5
CVE-2021-21975 [HIGH] VMware vRealize Operations updates address Server Side Request Forgery and Arbitrary File Write vulnerabilities (CVE-2021-21975, CVE-2021-21983)
VMSA-2021-0004: VMware vRealize Operations updates address Server Side Request Forgery and Arbitrary File Write vulnerabilities (CVE-2021-21975, CVE-2021-21983)
The vRealize Operations Manager API contains a Server Side Request Forgery. VMware has evaluated this issue to be of 'Important' severity with a maximum CVSSv3 base score of 8.6.
CVEs: CVE-2021-21975, CVE-2021-21983
Affected products: VMware Aria, VMware Cloud Foundation, VMware vRealize
No detection rules found.
Metasploit
VMware vRealize Operations (vROps) Manager SSRF RCE
metasploit·CVSS 7.5
CVE-2021-21975 [HIGH] VMware vRealize Operations (vROps) Manager SSRF RCE
VMware vRealize Operations (vROps) Manager SSRF RCE
This module exploits a pre-auth SSRF (CVE-2021-21975) and post-auth file write (CVE-2021-21983) in VMware vRealize Operations Manager to leak admin creds and write/execute a JSP payload. CVE-2021-21975 affects the /casa/nodes/thumbprints endpoint, and CVE-2021-21983 affects the /casa/private/config/slice/ha/certificate endpoint. Code execution occurs as the "admin" Unix user. The following vRealize Operations Manager versions are vulnerable: * 7.0.0 * 7.5.0 * 8.0.0, 8.0.1 * 8.1.0, 8.1.1 * 8.2.0 * 8.3.0 Version 8.3.0 is not exploitable for creds and is therefore not supported by this module. Tested successfully against 8.0.1, 8.1.0, 8.1.1, and 8.2.0.
Nuclei
vRealize Operations Manager API - Server-Side Request Forgery
nuclei·CVSS 7.5
CVE-2021-21975 [HIGH] vRealize Operations Manager API - Server-Side Request Forgery
vRealize Operations Manager API - Server-Side Request Forgery
vRealize Operations Manager API is susceptible to server-side request forgery. A malicious actor with network access to the vRealize Operations Manager API can steal administrative credentials or trigger remote code execution using CVE-2021-21983.
Template:
id: CVE-2021-21975
info:
name: vRealize Operations Manager API - Server-Side Request Forgery
author: luci
severity: high
description: vRealize Operations Manager API is susceptible to server-side request forgery. A malicious actor with network access to the vRealize Operations Manager API can steal administrative credentials or trigger remote code execution using CVE-2021-21983.
impact: |
Successful exploitation of this vulnerability could allow an attacker to send arbitr
Checkpoint
5th April – Threat Intelligence Report
blogs_checkpoint·2021-04-05
CVE-2021-21975 5th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 5th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 5th April, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Personal information of some 553 million Facebook users from 100 countries has been stolen and published online for free in a hacking forum. The records include full name, Facebook ID, phone number, email, location, bio and more.
Iranian APT group Charming Kitten, linked to the government, has launched a new phishing campaign
Tenable
CVE-2021-21975, CVE-2021-21983: Chained Vulnerabilities in VMware vRealize Operations Could Lead to Unauthenticated Remote Code Execution
blogs_tenable·2021-03-31·CVSS 7.5
[HIGH] CVE-2021-21975, CVE-2021-21983: Chained Vulnerabilities in VMware vRealize Operations Could Lead to Unauthenticated Remote Code Execution
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://packetstormsecurity.com/files/162349/VMware-vRealize-Operations-Manager-Server-Side-Request-Forgery-Code-Execution.htmlhttps://www.vmware.com/security/advisories/VMSA-2021-0004.htmlhttp://packetstormsecurity.com/files/162349/VMware-vRealize-Operations-Manager-Server-Side-Request-Forgery-Code-Execution.htmlhttps://www.vmware.com/security/advisories/VMSA-2021-0004.html
2021-03-31
Published
Exploited in the wild