CVE-2021-21978
CRITICALVMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file upload…
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Description
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file upload in logupload web application. An unauthorized attacker with network access to View Planner Harness could upload and execute a specially crafted file leading to remote code execution within the logupload container.
Affected Products
view plannervmwareResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote …
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote …
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote …
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote …
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote …
Frequently Asked Questions
Is CVE-2021-21978 in your stack?
O3 detects CVE-2021-21978 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.