Lucene search

K
cve[email protected]CVE-2022-31701
HistoryDec 14, 2022 - 7:15 p.m.

CVE-2022-31701

2022-12-1419:15:12
CWE-306
web.nvd.nist.gov
45
cve-2022-31701
vmware
workspace one access
identity manager
broken authentication
vulnerability
nvd
cvssv3
5.3
moderate severity

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

30.4%

VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3.

Affected configurations

NVD
Node
vmwareaccessMatch21.08.0.0linux
OR
vmwareaccessMatch21.08.0.1linux
OR
vmwareaccessMatch22.09.0.0linux
OR
vmwarecloud_foundation
Node
linuxlinux_kernelMatch-
AND
vmwareidentity_manager_connectorMatch3.3.6

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "VMware Workspace ONE Access (Access), VMware Identity Manager (vIDM)",
    "versions": [
      {
        "version": "VMware Workspace ONE Access (Multiple Versions)",
        "status": "affected"
      }
    ]
  }
]

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

30.4%

Related for CVE-2022-31701