Information Disclosure Vulnerability in VMware Workspace ONE Access
CVE-2022-22961

5.3MEDIUM

Key Information:

Summary

VMware Workspace ONE Access, Identity Manager, and vRealize Automation are affected by an information disclosure vulnerability that arises from returning excess information in responses. A remote attacker could exploit this vulnerability to extract the hostname of the target system, potentially leading to further targeting of victims. It is crucial for users to assess their exposure and apply necessary mitigations as outlined in VMware's security advisory.

Affected Version(s)

VMware Workspace ONE Access, Identity Manager and vRealize Automation Access 21.08.0.1, 21.08.0.0, 20.10.0.1, 20.10.0.0. Identity Manager 3.3.6, 3.3.5, 3.3.4, 3.3.3. vRealize Automation 7.6.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.