Login Interface Vulnerability in VMware Workspace ONE Access and Identity Manager
CVE-2021-22003
7.5HIGH
Key Information:
- Vendor
Vmware
- Vendor
- CVE Published:
- 31 August 2021
What is CVE-2021-22003?
VMware Workspace ONE Access and Identity Manager has a vulnerability that exposes a login interface on port 7443. An attacker with network access to this port may exploit the system by attempting user enumeration or executing brute force login attempts. The practical effectiveness of these methods can be influenced by account lockout policies and the complexity of the target account's password. Administrators are encouraged to review their configurations and implement necessary security measures to mitigate the risk.
Affected Version(s)
VMware Workspace ONE Access and Identity Manager Workspace ONE Access 20.10.01, 20.10 & 20.01. Identity Manager 3.3.5, 3.3.4, 3.3.3 & 3.3.2.