PoC Index

CVE-2021-22054

KEVHIGH 7.5EPSS 97.4%

VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
97.37% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2026-03-09
Nuclei
high · CWE-918
Published
2021-12-17
Updated
2026-03-11

Proof-of-concept exploits (2)

Nuclei templates (1)

References

Related