{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2021-22054",
  "revision": 1,
  "title": "Omnissa Workspace ONE — unauthenticated request forgery",
  "summary": "The unified endpoint management console from Omnissa (UEM, Workspace ONE), formerly VMware's, lets an unauthenticated visitor make the server issue requests of the attacker's choosing, reaching internal systems and what they hold.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 7.5,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
    "version": "3.1"
  },
  "epss": 0.97369,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2026-03-09",
    "prerequisites": "Network access to the management console; no credentials needed."
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "Workspace ONE UEM 20.0.8.37",
      "Workspace ONE UEM 20.11.0.40",
      "Workspace ONE UEM 21.2.0.27",
      "Workspace ONE UEM 21.5.0.37"
    ]
  },
  "mitre_attack": [
    "T1190"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Apply the fix from VMware advisory VMSA-2021-0029 now; exploitation probability is near certain and scanning has surged, so treat an exposed console as reached.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2021-22054",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2021-22054",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2021-22054",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-22054",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://www.vmware.com/security/advisories/VMSA-2021-0029.html"
    },
    {
      "type": "writeup",
      "url": "https://www.greynoise.io/blog/new-ssrf-exploitation-surge"
    }
  ],
  "published_at": "2021-12-17T17:15:12.590Z",
  "issued_at": "2026-09-24T08:51:39.744Z",
  "tags": [
    "omnissa",
    "vmware",
    "workspace-one",
    "ssrf",
    "kev"
  ]
}
