Known vulnerability record

CVE-2021-22054

Omnissa Workspace ONE Server-Side Request Forgery

Stable IDcve:CVE-2021-22054Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

Omnissa Workspace ONE Server-Side Request Forgery

Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.

Keep the signals separate

CVSS severityhighScore 7.5 · source CISA-ADP
EPSS probability97.4%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-03-09
Ransomware useunknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2021-12-17
CVE modified
2026-03-11
KEV date added
2026-03-09
Dataset fetched
2026-08-21T03:55:08.975Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.