CVE-2023-20886
8.8HIGH
Key Information
- Vendor
- Vmware
- Status
- Vmware Workspace One Uem Console
- Vendor
- CVE Published:
- 31 October 2023
Summary
VMware Workspace ONE UEM console contains an open redirect vulnerability. A malicious actor may be able to redirect a victim to an attacker and retrieve their SAML response to login as the victim user.
Affected Version(s)
VMware Workspace ONE UEM Console >= Workspace ONE UEM 23.6.0.0
VMware Workspace ONE UEM Console = Workspace ONE UEM 23.2.0.0
VMware Workspace ONE UEM Console = Workspace ONE UEM 22.12.0.0
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Risk change from: 6.1 to: 8.8 - (HIGH)
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database