Email:

Phone No.

Whatsapp

VMware Fixes Bug Allowing Attackers To Steal Admin Credentials

  • Home
  • VMware Fixes Bug Allowing Attackers To Steal Admin Credentials
VMware Fixes Bug Allowing Attackers To Steal Admin Credentials
VMware Fixes Bug Allowing Attackers To Steal Admin Credentials
VMware Fixes Bug Allowing Attackers To Steal Admin Credentials
VMware Fixes Bug Allowing Attackers To Steal Admin Credentials
VMware Fixes Bug Allowing Attackers To Steal Admin Credentials

VMware Fixes Bug Allowing Attackers To Steal Admin Credentials

VMware headpic

VMware has published security updates to address a high severity vulnerability in vRealize Operations that could allow attackers to steal admin credentials after exploiting vulnerable servers.

vRealize Operationsย is an AI-powered and “self-driving” IT operations management forย private, hybrid, and multi-cloud environments, available as an on-premises or SaaS solution.

The vulnerability was discovered and reported to VMware by Positive Technologies web security researcher Egor Dimitrenko.

SSRF exploitable by unauthenticated attackers

The privately reported vulnerability tracked asย CVE-2021-21975ย is caused by aย Server Side Request Forgeryย bugย in theย vRealize Operations Manager API.

Attackers canย exploit the vulnerabilityย remotely without requiring authentications or user interaction in low complexity attacks to steal administrative credentials.

Also Read: Practitioner Certificate In Personal Data Protection: Everything You Need To Know

VMware rated the security flaw as high severity giving it a base score of 8.6 out of 10.

Details on how to get the security patch for vRealize Operations are available in the support articles linked below:

PT SWARM
Image: PT SWARM

Workaround also available

VMware has also published workaround instructions for admins who don’t want to or can’t immediately patch servers runningย vulnerableย vRealize Operations versions (e.g., there is no patch for their version).

As the company explained, there are is no impact after applying the workaround measures and no functionality will be affected.

To work around this issue, you will have to remove a configuration line from the casa-security-context.xml file and restart the CaSA service on the affected device.

Detailed information on how to do that is available in the support articles linked above for each security patch/version.

VMwareย today fixed a second high-severityย vulnerability in theย vRealize Operations Manager APIย (tracked asย CVE-2021-21974) and allowing authenticated attackers to remotely “write files to arbitrary locations on the underlying photon operating system.”

Also Read: The DNC Singapore: Looking At 2 Sides Better

When chained together,ย CVE-2021-21975 and CVE-2021-21983 lead to pre-auth remote code execution (RCE) on unpatched vRealize Operations servers.

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Cybersecurity updates weekly!

PDPA-1024x683-min

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Cybersecurity updates weekly!

PDPA-1024x683-min

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
× Chat with us