Record summary

CVE-2022-31656 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 13, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

Workspace ONE Access and Identity Manager

Browse VMware / Workspace ONE Access and Identity Manager
VulnCheckVersion data not supplied

VMware Workspace ONE Access, Identity Manager and vRealize Automation

CVE ListWorkspace One Access (21.08.0.1 & 21.08.0.0), Identity Manager (vIDM) (3.3.6, 3.3.5 & 3.3.4), and vRealize Automation 7.6affected

Nuclei templates

1
ProjectDiscoveryCRITICALVMware - Local File InclusionCVSS 9.8

VMware Workspace ONE Access, Identity Manager, and Realize Automation are vulnerable to local file inclusion because they contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

Impact

The impact of this vulnerability is that an attacker can read sensitive files on the server, which may contain credentials, configuration files, or other sensitive information.

Remediation

To remediate this vulnerability, ensure that all user-supplied input is properly validated and sanitized before being used in file inclusion operations.

WeaknessesCWE-287
AuthorsDhiyaneshDk
Template tagscve2022cvevmwarelfivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:vmware:identity_manager:3.3.4:*:*:*:*:*:*:*
Shodan: http.favicon.hash:-1250474341
FOFA: icon_hash=-1250474341
FOFA: app="vmware-workspace-one-access" || app="vmware-identity-manager" || app="vmware-vrealize"

Source: ProjectDiscovery

References

2