Disclosure summary
Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.
CISA remediation guidance
Apply updates per vendor instructions.
Original records & references
PUBLISHED 2022-01-18T00:00:00-05:00
MODIFIED 2022-01-18T00:00:00-05:00
INGESTED 2026-10-06T11:42:59-04:00