LiveActive security incident?Get immediate response
CVE Record

CVE-2021-22023: The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability.

The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor with administrative access to vRealize Operations Manager API may be able to modify other users information leading to an account takeover.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2021-22023 affects VMware vRealize Operations 8.x before 8.5. An authenticated administrator using the API may be able to change other users' information, which could result in account takeover. The main risk is abuse after administrative access is obtained, not unauthenticated internet compromise.

Executive priority

Treat this as a medium-priority identity and platform governance issue. It is serious because it can support account takeover, but the cited description requires existing administrative API access.

Technical view

The issue is described as an insecure object reference in the vRealize Operations Manager API. The source states that a malicious actor with administrative API access may modify other users' information. No CVSS score, CWE, endpoint detail, or exploit technique is provided in the source bundle.

Likely exposure

Organizations running VMware vRealize Operations 8.x prior to 8.5 are potentially exposed, especially where administrative API access is broadly granted or reachable beyond tightly controlled management networks.

Exploitation context

The source bundle does not show CISA KEV listing or evidence of active exploitation. Exploitation is described as requiring administrative access to the vRealize Operations Manager API.

Researcher notes

Evidence is limited. The bundle names an insecure object reference and affected versions, but provides no CVSS, CWE, endpoint, proof of exploitation, or detailed patch notes. Avoid assuming unauthenticated exposure or public exploitability from these sources alone.

Mitigation direction

  • Upgrade affected vRealize Operations 8.x deployments to 8.5 or later where applicable.
  • Review VMware advisory VMSA-2021-0018 for vendor-specific remediation guidance.
  • Restrict vRealize Operations API access to trusted management networks.
  • Limit administrative API privileges to required personnel only.
  • Audit administrative accounts for unexpected changes or excessive privileges.

Validation and detection

  • Inventory vRealize Operations deployments and confirm version numbers.
  • Identify any instances running 8.x prior to 8.5.
  • Review who has administrative API access.
  • Check logs for unexpected user profile or account changes.
  • Confirm remediation by verifying the post-upgrade version.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-22023 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/aVMware vRealize OperationsVMware vRealize Operations (8.x prior to 8.5)Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.