Showing 4 vulnerabilities on this page for Workspace ONE Access and Identity Manager

Signals CISA KEV Ransomware Nuclei
VMware vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

VMware Workspace ONE Access, Identity Manager and vRealize Automation Authentication Bypass

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

CWE-287Aug 5, 20221 related artifact
CVSS9.8v3.1EPSS22.9%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

VMware Workspace ONE Access, Identity Manager and vRealize Authentication Bypass Vulnerability

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

CWE-287May 20, 20221 related artifact
CVSS9.8v3.1EPSS56.3%PoCs4SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

VMware Workspace ONE Access and Identity Manager Improper Authentication

VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.

CWE-287Apr 13, 20221 related artifact
CVSS9.8v3.1EPSS50.7%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

CWE-94Apr 11, 20221 related artifact
CVSS9.8v3.1EPSS>99.9%PoCs28SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX