A malicious attacker who has the ability to access the VMware™ vRealize Operations Manager API over the network can perform a Server Side Request Forgery(SSRF) attack to steal sensitive credentials of management.
VMware cloud_foundation version 4.x 3.x, VMware vRealize_suite_lifecycle_manager version 8.x, VMware vRealize_operations_manager versions 8.0.0, 8.0.1, 8.3.0, 8.1.0, 8.1.1, 8.2.0, 7.5.0
Successful exploitation will allow a malicious attacker to execute unauthorized actions such as gaining access to sensitive data, arbitrary code execution, etc.