← Back

CVE-2021-22054

Published: Dec 17, 2021Modified: Mar 10, 2026CISA KEV

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.

Affected (4)

1 product
Workspace One Uem Console
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
From 20.0.8.0 to 20.0.8.36
From 20.11.0.0 to 20.11.0.40
From 21.2.0.0 to 21.2.0.27
From 21.5.0.0 to 21.5.0.37

References (4)

Source: security@vmware.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Third Party Advisory

Timeline

No history available yet.