CVE-2021-22054
9.5 CISA KEVOmnissa · Workspace ONE UEM
An unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the Workspace ONE UEM console allows attackers to access sensitive information via the BlobHandler.ashx endpoint.
Executive summary
This critical SSRF vulnerability in Omnissa Workspace ONE UEM is actively exploited in the wild and allows unauthenticated attackers to gain unauthorized access to sensitive system information.
Vulnerability
This is a pre-authentication Server-Side Request Forgery (SSRF) flaw occurring in the BlobHandler.ashx endpoint. An unauthenticated attacker with network access to the UEM console can trigger requests to internal resources, bypassing authentication controls to retrieve sensitive data.
Business impact
The vulnerability carries a CVSS score of 9.5, reflecting its critical severity and the ease with which it can be exploited. Successful exploitation allows for unauthorized disclosure of sensitive internal data, which could lead to further network compromise, data breaches, and significant operational disruption. Because the vulnerability is being actively exploited, the risk to organizational infrastructure is immediate and severe.
Remediation
Immediate Action: Administrators must update the Workspace ONE UEM console to the patched versions specified in VMSA-2021-0029. Furthermore, organizations should follow the instructions provided in KB88323 to rotate the static master key, which is a necessary step to fully remediate the underlying risk.
Proactive Monitoring: Monitor network traffic logs for suspicious requests directed toward the BlobHandler.ashx endpoint. Unusual outbound traffic from the UEM server to internal or external assets should be investigated immediately as a potential indicator of exploitation.
Compensating Controls: Deploy Web Application Firewall (WAF) rules designed to inspect and block requests to the vulnerable BlobHandler.ashx endpoint that contain anomalous parameters. While not a permanent fix, these controls can provide temporary protection while the update and key rotation processes are finalized.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept repository exists on GitHub.
Analyst recommendation
Given the critical CVSS severity and the confirmation of active exploitation in the wild, this vulnerability represents an extreme risk to the environment. Organizations must prioritize the application of the vendor-supplied patches and the mandatory rotation of the static master key without delay. Failure to address this vulnerability exposes the UEM environment to unauthorized data exfiltration and potential follow-on attacks.