Vulnerability Intelligence Report
CVE-2021-21983
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.
SSVC: Active Exploitation
Automatable
CVSS Base Score
6.5
—
EPSS Probability:68.56%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| n/a | VMware vRealize Operations | VMware vRealize Operations prior to 8.4 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
68.557%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VMware by Broadcom · Vendor · USA |
| Reserved | 2021-01-04T00:00:00 |
| Published | 2021-03-31T17:50:36 |
| Last Updated | 2026-08-12T03:55:28 |
Community Chatter & Buzz