Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

VMware urges customers to patch critical vulnerabilities in vRealize Operations platform

Two highly rated security issues that interact with each other inherently increases the severity of the issue

by The Gurus
March 31, 2021
in News
VMware Introduces Industry’s First Service-Defined Firewall To Help Better Protect Apps And Data On-Premises And In the Cloud.
Share on FacebookShare on Twitter

Cloud computing and visualisation software and services provider VMware has patched a serious vulnerability that could have led an attacker to steal admin credentials in vRealize Operations.

In an advisory published on Tuesday, the company stated that “multiple vulnerabilities in VMware vRealize Operations were privately reported to VMware.” In the same announcement, VMware said that patches and workarounds are now available to address these vulnerabilities in impacted products and warned customers that the issues were evaluated to be of “Important” severity.

CVE-2021-21975 would allow a malicious actor with network access to the vRealize Operations Manager API to perform a Server Side Request Forgery attack to steal administrative credentials.

CVE-2021-21983 could allow an authenticated malicious actor with network access to the vRealize Operations Manager API to write files to arbitrary locations on the underlying photon operating system.

Security professionals provided the following advice on these security issues:

Michael Barragry, operations lead at Edgescan: 

A prerequisite for these vulnerabilities is network access to the vRealize Operations Manager API. This illustrates how a layered, defense-in-depth strategy can help mitigate unforeseen vulnerabilities – in this case restricting access to the API could make the difference between being exploited or not.

APIs can often prove to be a bit of a blind spot for organisations, as various endpoints are often spun up as part of out-of-the-box deployments. These can be missed, or just forgotten about over time. Maintaining an accurate picture of all exposed infrastructure and services is critical to minimize risk of attack.

Lewis Jones, threat intelligence analyst at Talion:

The successful exploit of these vulnerabilities could allow an attacker remote access without user interaction to steal administrative credentials. This comes just months after Russian hackers reportedly exploited a VMWare bug to plant web shells inside hacked networks and pivot to Microsoft ADFS servers from where they steal sensitive data.

Users of VMware are advised to apply the security updates swiftly but have provided a workaround for users unable to do so. To work around this issue, you will have to remove a configuration line from the casa-security-context.xml file and restart the CaSA service on the affected device.

Vulnerabilities are routinely exploited by threat attackers. Exploitation of vulnerabilities often requires fewer resources as compared with zero-day exploits for which no patches are available. As highlighted by the recent Microsoft Exchange attacks, once a vulnerability is publicly disclosed threat attackers quickly switch attack method to exploit the vulnerability before patches are applied. This emphasizes the importance of swift action by organisations, who should quickly follow the recommended actions and implement the security updates.

Stephen Kapp, CTO and CISO at Cortex Insight:

The highlighted issues within the fixed released by VMWare show the importance of understanding vulnerability interactions and the concept of vulnerability chaining. Understanding vulnerability interactions within an environment are important, in this VMWare instance both issues are rated by VMware as ‘Important’ and both have a ‘High’ banded CVSS rated score. Individually this would be enough for most organisations to have the updates applied quickly, although details are sparse within the released information so gaining an understanding of the issue interactions is key to making an informed decision to prioritise remediation measures.

Two highly rated security issues that interact in a way that could improve the effectiveness of the other inherently increases the severity of the issue and thus warrants a more timely remediation response. But this can be said of lower severity issues, combining issues to improve the effectiveness is nothing new, but so many organisations fail to account for these interactions in their remediation efforts.

ShareTweet
Previous Post

UK Cyber Security Council Becomes Independent Entity

Next Post

Why are you ignoring NIST, NSA and the NCSC?

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol