← Back to CVE List
Vulnerability Intelligence Report

CVE-2022-31657

VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network access may be able to redirect an authenticated user to an arbitrary domain.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:1.14%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
vmware identity_manager 3.3.4, 3.3.5, 3.3.6
vmware one_access 21.08.0.0, 21.08.0.1
linux linux_kernel all
vmware access_connector 21.08.0.0, 21.08.0.1, 22.05
vmware identity_manager_connector 3.3.4, 3.3.5, 3.3.6, 19.03.0.1
microsoft windows all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.139%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVMware by Broadcom · Vendor · USA
Reserved2022-05-25T00:00:00
Published2022-08-05T15:07:39
Last Updated2024-08-03T07:26:00

LINK COPIED TO CLIPBOARD