Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
n/a VMware vRealize Operations — Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious …
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L H N U N H H 6.5 .6856 99.3 —
AFFECTED
Product Versions Fixed
VMware vRealize Operations VMware vRealize Operations prior to 8.4 – —
TIMELINE
Jan 4 Reserved by vmware
Mar 31 Published (CNA: vmware)
Aug 12 ENRICHED — CVE-2021-21983 (VMware vRealize Operations). Received CVSS 6.5 and CPE data from NVD.
Aug 12 EXPLOIT PUBLISHED — CVE-2021-21983 (VMware vRealize Operations). Public exploit reference added.
Description
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.
Lifecycle
Complete event history — 4 events, chronological
| Date | Event | Detail |
| January 4, 2021 | Reserved | Reserved by vmware |
| March 31, 2021 | Published | Published (CNA: vmware) |
| August 12, 2026 | ENRICHED | ENRICHED — CVE-2021-21983 (VMware vRealize Operations). Received CVSS 6.5 and CPE data from NVD. |
| August 12, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2021-21983 (VMware vRealize Operations). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| n/a | VMware vRealize Operations | — | VMware vRealize Operations prior to 8.4 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2021-21983 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.