3a. Server-side Template Injection Remote Code Execution Vulnerability (CVE-2022-22954)
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
3b. OAuth2 ACS Authentication Bypass Vulnerabilities (CVE-2022-22955, CVE-2022-22956)
VMware Workspace ONE Access has two authentication bypass vulnerabilities in the OAuth2 ACS framework. VMware has evaluated the severity of these issues to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
3c. JDBC Injection Remote Code Execution Vulnerabilities (CVE-2022-22957, CVE-2022-22958)
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities. VMware has evaluated the severity of these issues to be in the Critical severity range with a maximum CVSSv3 base score of 9.1.
3d. Cross Site Request Forgery Vulnerability (CVE-2022-22959)
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.8.
3e. Local Privilege Escalation Vulnerability (CVE-2022-22960)
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.8.
3f. Information Disclosure Vulnerability (CVE-2022-22961)
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3.
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22954
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22955
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22956
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22957
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22958
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22959
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22960
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22961
kb.vmware.com/s/article/88098
kb.vmware.com/s/article/88099
www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H