VMware Workspace ONE UEM (formerly AirWatch) is affected by CVE-2021-22054, a critical pre-authentication server-side request forgery flaw (CVSS 9.1) in the BlobHandler.ashx endpoint used by the AirWatch Console and Catalog applications. Attackers can exploit hardcoded encryption parameters—by selecting key version kv0—to create valid encrypted URL parameters that cause a vulnerable UEM server to send arbitrary HTTP requests, including attacker-controlled methods and bodies, to internal or external targets.
The publicly exposed /Catalog/BlobHandler.ashx endpoint may be reachable even where the administrative console is restricted, enabling access to internal services or cloud metadata endpoints; on AWS-hosted deployments, this could expose IAM-role credentials. VMware issued fixes in VMSA-2021-0029 in December 2021 and later warned that public technical details increased exploitation risk. Organizations that have not patched should apply the vendor updates or mitigations and rotate the static master key according to KB88323.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Assetnote disclosed technical details of CVE-2021-22054, including the hardcoded default "kv0" master key that allowed unauthenticated attackers to encrypt arbitrary SSRF targets. The researchers demonstrated access to AWS instance metadata through vulnerable Workspace ONE UEM deployments and stated that both SaaS and on-premises deployments were exploitable.
VMware published a blog post urging customers to apply the December 2021 fixes or workarounds after public vulnerability details became available. It also provided KB88323 instructions for rotating the static master key associated with the issue.
VMware released patches for CVE-2021-22054 through advisory VMSA-2021-0029, including fixed Workspace ONE UEM releases for affected versions. The patches and documented workarounds prevented exploitation of the SSRF issue.
VMware confirmed that it was developing a patch for the reported Workspace ONE UEM SSRF vulnerability.
Assetnote researchers reported the pre-authentication SSRF vulnerability later designated CVE-2021-22054 to VMware. The flaw affected BlobHandler.ashx endpoints in Workspace ONE UEM.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
slcyber.io
Open sourceslcyber.io
Open sourceblog.assetnote.io
Open sourceblogs.vmware.com
Open sourcevmware.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.