Threat Intelligence / CVE / CVE-2021-22054

CVE-2021-22054

CISA KEV
CVSS 7.5 (HIGH) · EPSS 93.8% · Published 2021-12-17

VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.

CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)

CWE-918

Threats tracking this CVE

References

Full detection coverage & IOCs for threats exploiting CVE-2021-22054 are available via the Threadlinqs MCP server (Purple tier). View plans →

Markdown version · Threadlinqs Intelligence