===================================================================== CERT-Renater Note d'Information No. 2021/VULN545 _____________________________________________________________________ DATE : 20/10/2021 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running VMware vRealize Operations Tenant App versions prior to 8.6. ===================================================================== https://groups.google.com/g/golang-announce/c/AEBu9j7yj5A _____________________________________________________________________ Moderate Advisory ID: VMSA-2021-0024 CVSSv3 Range: 5.3 Issue Date: 2021-10-19 Updated On: 2021-10-19 CVE(s): CVE-2021-22034 Synopsis: VMware vRealize Operations Tenant App update addresses Information Disclosure Vulnerability (CVE-2021-22034) 1. Impacted Products VMware vRealize Operations Tenant App for VMware Cloud Director 2. Introduction An information disclosure vulnerability in VMware vRealize Operations Tenant App for VMware Cloud Director was privately reported to VMware. Patch is available to address this vulnerability in impacted VMware products. 3. Information Disclosure Vulnerability in VMware vRealize Operations Tenant App for VMware Cloud Director (CVE-2021-22034) Description The vRealize Operations Tenant App for VMware Cloud Director contains an information disclosure vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3. Known Attack Vectors A malicious actor with network access to port 443 on the vRealize Operations Tenant App may access any set system environment variables, leading to information disclosure. Resolution To remediate CVE-2021-22034 apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' found below. Workarounds None. Additional Documentation None. Acknowledgements VMware would like to thank Dhiraj Shrikant Datar for reporting this vulnerability to us. Notes None. Response Matrix: Product Version Running On CVE Identifier CVSSv3 Severity Fixed Version Workarounds Additional Documentation vRealize Operations Manager Tenant App 2.x Any CVE-2021-22034 5.3 moderate 8.6 N/A N/A 4. References Remediation and Workarounds: vRealize Operations Manager Tenant App 8.6: https://docs.vmware.com/en/Management-Packs-for-vRealize-Operations/8.6/rn/Tenant-App-86-Release-Notes.html FIRST CVSSv3 Calculator: CVE-2021-22034: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N (5.3) Mitre CVE Dictionary Links: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22034 5. Change Log 2021-10-19: VMSA-2021-0024 Initial security advisory. 6. Contact E-mail list for product security notifications and announcements: https://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce This Security Advisory is posted to the following lists: security-announce@lists.vmware.com bugtraq@securityfocus.com fulldisclosure@seclists.org E-mail: security@vmware.com PGP key at: https://kb.vmware.com/kb/1055 VMware Security Advisories https://www.vmware.com/security/advisories VMware Security Response Policy https://www.vmware.com/support/policies/security_response.html VMware Lifecycle Support Phases https://www.vmware.com/support/policies/lifecycle.html VMware Security & Compliance Blog https://blogs.vmware.com/security Twitter https://twitter.com/VMwareSRC Copyright 2021 VMware Inc. All rights reserved. ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================