Lucene search

K
vmwareVMwareVMSA-2022-0011
HistoryApr 06, 2022 - 12:00 a.m.

VMware Workspace ONE Access, Identity Manager and vRealize Automation updates address multiple vulnerabilities.

2022-04-0600:00:00
www.vmware.com
103
vmware
workspace one access
identity manager
vrealize automation
updates
critical vulnerabilities
remote code execution
template injection
authentication bypass
oauth2
acs
jdbc injection
cross site request forgery
local privilege escalation
information disclosure

EPSS

0.975

Percentile

100.0%

3a. Server-side Template Injection Remote Code Execution Vulnerability (CVE-2022-22954)

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

3b. OAuth2 ACS Authentication Bypass Vulnerabilities (CVE-2022-22955, CVE-2022-22956)

VMware Workspace ONE Access has two authentication bypass vulnerabilities in the OAuth2 ACS framework. VMware has evaluated the severity of these issues to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

3c. JDBC Injection Remote Code Execution Vulnerabilities (CVE-2022-22957, CVE-2022-22958)

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities. VMware has evaluated the severity of these issues to be in the Critical severity range with a maximum CVSSv3 base score of 9.1.

3d. Cross Site Request Forgery Vulnerability (CVE-2022-22959)

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.8.

3e. Local Privilege Escalation Vulnerability (CVE-2022-22960)

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.8.

3f. Information Disclosure Vulnerability (CVE-2022-22961)

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3.

References