Cross-Site Request Forgery in VMware Workspace ONE Access and Identity Manager
CVE-2022-22959
Key Information:
- Vendor
- Vmware
- Vendor
- CVE Published:
- 13 April 2022
Summary
VMware Workspace ONE Access, Identity Manager, and vRealize Automation are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability. This flaw can be exploited by a malicious actor to deceive a legitimate user into unknowingly validating a harmful JDBC URI. The attacker can leverage this vulnerability to execute unauthorized actions, potentially leading to further security risks. Users of the affected products are recommended to review their security practices and apply relevant patches provided in VMware's security advisory.
Affected Version(s)
VMware Workspace ONE Access, Identity Manager and vRealize Automation Access 21.08.0.1, 21.08.0.0, 20.10.0.1, 20.10.0.0. Identity Manager 3.3.6, 3.3.5, 3.3.4, 3.3.3. vRealize Automation 7.6.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved