CVE-2022-22957

HIGH EXPLOITED

VMware Workspace ONE Access and Identity Manager - Remote Code Execution via JDBC URI Deserialization

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2022-22957 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution.

Scores

CVSS v3 7.2
EPSS 0.4323
EPSS Percentile 97.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2025-09-03
CWE
CWE-502
Status published
Products (12)
vmware/cloud_foundation 3.0 - 5.0
vmware/identity_manager 3.3.3
vmware/identity_manager 3.3.4
vmware/identity_manager 3.3.5
vmware/identity_manager 3.3.6
vmware/vrealize_automation 7.6
vmware/vrealize_automation 8.0 - 9.0
vmware/vrealize_suite_lifecycle_manager 8.0 - 9.0
vmware/workspace_one_access 20.10.0.0
vmware/workspace_one_access 20.10.0.1
... and 2 more
Published Apr 13, 2022
Tracked Since Feb 18, 2026