CVE-2021-21983
HIGH 8.5EPSS 68.6%
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.
- CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H - CVSS v2.0
- 8.5 HIGH
AV:N/AC:L/Au:S/C:N/I:C/A:C - EPSS
- 68.56% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2021-03-31
- Updated
- 2026-08-12
Proof-of-concept exploits (3)
- http://packetstormsecurity.com/files/162349/VMware-vRealize-Operations-Manager-Server-Sid…
- murataydemir/CVE-2021-219833★ · 2022-03-16
- rabidwh0re/REALITY_SMASHER37★ · 2021-04-07