{"id":"CVE-2021-22054","details":"VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.","modified":"2026-03-14T10:44:18.309977Z","published":"2021-12-17T17:15:12.590Z","references":[{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22054"},{"type":"ADVISORY","url":"https://www.greynoise.io/blog/new-ssrf-exploitation-surge"},{"type":"FIX","url":"https://www.vmware.com/security/advisories/VMSA-2021-0029.html"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-22054.json","unresolved_ranges":[{"events":[{"introduced":"20.0.8.0"},{"fixed":"20.0.8.36"}]},{"events":[{"introduced":"20.11.0.0"},{"fixed":"20.11.0.40"}]},{"events":[{"introduced":"21.2.0.0"},{"fixed":"21.2.0.27"}]},{"events":[{"introduced":"21.5.0.0"},{"fixed":"21.5.0.37"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}