Lucene search

K
cvelistVmwareCVELIST:CVE-2022-22956
HistoryApr 13, 2022 - 12:00 a.m.

CVE-2022-22956

2022-04-1300:00:00
vmware
www.cve.org
1

10 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

58.8%

VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "VMware Workspace ONE Access",
    "versions": [
      {
        "version": "Access 21.08.0.1, 21.08.0.0, 20.10.0.1, 20.10.0.0.",
        "status": "affected"
      }
    ]
  }
]

10 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

58.8%