CVE-2021-22054
Omnissa Workspace ONE Server-Side Request Forgery
Record summary
CVE-2021-22054 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC and 1 Nuclei template. CISA lists CVE-2021-22054 in KEV.
Description
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.
Exploitation context
Known exploitation
- CISA KEV
- Listed · Mar 9, 2026 · CISA
- VulnCheck KEV
- Listed · Mar 11, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 20, 2021 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Workspace One UEMBrowse Omnissa / Workspace One UEM | CISA | Version data not supplied | |
VMware Workspace ONE UEM console | CVE List | VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37. | affected |
Proofs of concept
1Repository PoCs
GitHubMKSx/CVE-2021-22054Repository PoCby MKSxStars: 5Not analyzed3 files
Nuclei templates
1ProjectDiscoveryHIGHVMWare Workspace ONE UEM - Server-Side Request ForgeryCVSS 7.5
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain a server-side request forgery vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.
Impact
An attacker can exploit this vulnerability to send crafted requests to internal resources, potentially leading to unauthorized access or information disclosure.
Remediation
Apply the necessary patches or updates provided by VMWare to fix the vulnerability.
Source: ProjectDiscovery