VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.
2021-12-17T17:15:12.590
2024-11-21T05:49:30.550
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | vmware | workspace_one_uem_console | < 20.0.8.36 | Yes |
Application | vmware | workspace_one_uem_console | < 20.11.0.40 | Yes |
Application | vmware | workspace_one_uem_console | < 21.2.0.27 | Yes |
Application | vmware | workspace_one_uem_console | < 21.5.0.37 | Yes |