CVE-2021-22054

VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.
SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vmwareCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
vmwareworkspace_one_uem_console
20.0.8.0 ≤
𝑥
< 20.0.8.36
vmwareworkspace_one_uem_console
20.11.0.0 ≤
𝑥
< 20.11.0.40
vmwareworkspace_one_uem_console
21.2.0.0 ≤
𝑥
< 21.2.0.27
vmwareworkspace_one_uem_console
21.5.0.0 ≤
𝑥
< 21.5.0.37
𝑥
= Vulnerable software versions