Cross-Site Request Forgery in VMware Workspace ONE Access and Identity Manager
CVE-2022-22959

4.3MEDIUM

Key Information:

Summary

VMware Workspace ONE Access, Identity Manager, and vRealize Automation are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability. This flaw can be exploited by a malicious actor to deceive a legitimate user into unknowingly validating a harmful JDBC URI. The attacker can leverage this vulnerability to execute unauthorized actions, potentially leading to further security risks. Users of the affected products are recommended to review their security practices and apply relevant patches provided in VMware's security advisory.

Affected Version(s)

VMware Workspace ONE Access, Identity Manager and vRealize Automation Access 21.08.0.1, 21.08.0.0, 20.10.0.1, 20.10.0.0. Identity Manager 3.3.6, 3.3.5, 3.3.4, 3.3.3. vRealize Automation 7.6.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.