CVE-2021-22036
published 2021-10-13CVE-2021-22036: VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. A malicious actor may be able to…
PriorityP427medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.90%
55.3th percentile
VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. A malicious actor may be able to redirect victim to an attacker controlled domain due to improper path handling in vRealize Orchestrator leading to sensitive information disclosure.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vrealize_automation | >= 8.0 < 8.6 | 8.6 |
| vmware | vrealize_orchestrator | >= 8.0 < 8.6 | 8.6 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xhgj-fcgm-66qp: VMware vRealize Orchestrator ((8
ghsa_unreviewed·2022-05-24
CVE-2021-22036 [MEDIUM] CWE-200 GHSA-xhgj-fcgm-66qp: VMware vRealize Orchestrator ((8
VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. A malicious actor may be able to redirect victim to an attacker controlled domain due to improper path handling in vRealize Orchestrator leading to sensitive information disclosure.
VMware
VMware vRealize Orchestrator update addresses open redirect vulnerability (CVE-2021-22036)
vendor_vmware·2021-10-12·CVSS 6.5
CVE-2021-22036 [MEDIUM] VMware vRealize Orchestrator update addresses open redirect vulnerability (CVE-2021-22036)
VMSA-2021-0023: VMware vRealize Orchestrator update addresses open redirect vulnerability (CVE-2021-22036)
VMware vRealize Orchestrator contains an open redirect vulnerability due to improper path handling. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 6.5.
CVEs: CVE-2021-22036
Affected products: VMware Aria, VMware Cloud Foundation, VMware vRealize
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-10-13
Published