Cross-Site Request Forgery in VMware Workspace ONE Access and Identity Manager
CVE-2022-22959
Key Information:
- Vendor
Vmware
- Vendor
- CVE Published:
- 13 April 2022
What is CVE-2022-22959?
VMware Workspace ONE Access, Identity Manager, and vRealize Automation are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability. This flaw can be exploited by a malicious actor to deceive a legitimate user into unknowingly validating a harmful JDBC URI. The attacker can leverage this vulnerability to execute unauthorized actions, potentially leading to further security risks. Users of the affected products are recommended to review their security practices and apply relevant patches provided in VMware's security advisory.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
VMware Workspace ONE Access, Identity Manager and vRealize Automation Access 21.08.0.1, 21.08.0.0, 20.10.0.1, 20.10.0.0. Identity Manager 3.3.6, 3.3.5, 3.3.4, 3.3.3. vRealize Automation 7.6.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved