CVE-2021-22003
Summary
| CVE | CVE-2021-22003 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-31 22:15:00 UTC |
| Updated | 2021-09-09 12:58:00 UTC |
| Description | VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based on lockout policy configuration and password complexity for the target account. |
Risk And Classification
Problem Types: CWE-307
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | - | All | All | All |
| Application | Vmware | Cloud Foundation | 4.0 | All | All | All |
| Application | Vmware | Cloud Foundation | 4.0.1 | All | All | All |
| Application | Vmware | Cloud Foundation | 4.1 | All | All | All |
| Application | Vmware | Cloud Foundation | 4.1.0.1 | All | All | All |
| Application | Vmware | Cloud Foundation | 4.2.1 | All | All | All |
| Application | Vmware | Identity Manager | 3.3.2 | All | All | All |
| Application | Vmware | Identity Manager | 3.3.3 | All | All | All |
| Application | Vmware | Identity Manager | 3.3.4 | All | All | All |
| Application | Vmware | Identity Manager | 3.3.5 | All | All | All |
| Application | Vmware | Vrealize Suite Lifecycle Manager | 8.0 | All | All | All |
| Application | Vmware | Vrealize Suite Lifecycle Manager | 8.0.1 | All | All | All |
| Application | Vmware | Vrealize Suite Lifecycle Manager | 8.1 | All | All | All |
| Application | Vmware | Vrealize Suite Lifecycle Manager | 8.2 | All | All | All |
| Application | Vmware | Workspace One Access | 20.01 | All | All | All |
| Application | Vmware | Workspace One Access | 20.10 | All | All | All |
| Application | Vmware | Workspace One Access | 20.10.01 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VMSA-2021-0016 | MISC | www.vmware.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 376153 VMware Identity Manager (vIDM) and Workspace ONE Access Multiple Vulnerabilities (VMSA-2021-0016)