Vulnerability Intelligence Report
CVE-2022-22972
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
Nuclei Template
CVSS Base Score
9.8
CRITICAL
EPSS Probability:52.81%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| vmware | identity_manager | 3.3.3, 3.3.4, 3.3.5, 3.3.6 |
| vmware | vrealize_automation | 7.6 |
| vmware | workspace_one_access | 20.10.0.0, 20.10.0.1, 21.08.0.0, 21.08.0.1 |
| linux | linux_kernel | all |
| vmware | cloud_foundation | 3.0, 3.0.1, 3.0.1.1, 3.5, 3.5.1, 3.7, 3.7.1, 3.7.2, 3.8, 3.8.1, 3.9, 3.9.1, 3.10, 3.10.1, 3.10.1.1, 3.10.1.2, 3.10.2.1, 3.10.2.2, 3.11, 3.11.0.1, 4.0, 4.0.1, 4.1, 4.1.0.1, 4.2, 4.2.1, 4.3, 4.3.1 |
| vmware | vrealize_suite_lifecycle_manager | 8.0, 8.0.1, 8.1, 8.2, 8.3, 8.4, 8.4.1, 8.6, 8.6.1, 8.6.2, 8.7, 8.8 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VMware by Broadcom · Vendor · USA |
| Reserved | 2022-01-10T00:00:00 |
| Published | 2022-05-20T20:18:39 |
| Last Updated | 2024-08-03T03:28:42 |
Community Chatter & Buzz