VYPR
High severity7.5NVD Advisory· Published Aug 30, 2021· Updated Jun 17, 2026

CVE-2021-22025

CVE-2021-22025

Description

The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthenticated API access. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can add new nodes to existing vROps cluster.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • VMware/vRealize Operations Manager APIdescription
  • <8.5+ 2 more
    • (no CPE)range: <8.5
    • cpe:2.3:a:vmware:vrealize_operations_manager:*:*:*:*:*:*:*:*range: >=8.0.0,<8.5.0
    • cpe:2.3:a:vmware:vrealize_operations_manager:7.5.0:*:*:*:*:*:*:*
  • cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
    Range: >=3.0,<=3.10.2.1
  • cpe:2.3:a:vmware:vrealize_suite_lifecycle_manager:*:*:*:*:*:*:*:*
    Range: >=8.0,<=8.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.