QID 376153
Date Published: 2021-12-10
QID 376153: VMware Identity Manager (vIDM) and Workspace ONE Access Multiple Vulnerabilities (VMSA-2021-0016)
VMware Workspace One Access contain a Command Injection Vulnerability in the administrative configurator.
VMware Identity Manager contain a Command Injection Vulnerability in the administrative configurator.
CVE-2021-22002: VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. VMware has evaluated this issue to be of 'Important' severity with a maximum CVSSv3 base score of 8.6.
CVE-2021-22003: VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. VMware has evaluated this issue to be of 'Low' severity with a maximum CVSSv3 base score of 3.7
Affected Versions:
VMware Identity Manager (vIDM) 3.3.2 prior to build 15951611
VMware Identity Manager (vIDM) 3.3.3 prior to build 17121420
VMware Identity Manager (vIDM) 3.3.4 prior to build 17498518
VMware Identity Manager (vIDM) 3.3.5 prior to build 18049997
VMware Workspace ONE Access (Access) 20.01 prior to build 15509389
VMware Workspace ONE Access (Access) 20.10 prior to build 17035009
VMware Workspace ONE Access (Access) 20.10.01 prior to build 17586971
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of VMware Identity Manager and VMware Workspace ONE Access (Access) with build version on the target.
A malicious actor with network access to port 443 could tamper with host headers to facilitate access to the /cfg web app, in addition a malicious actor could access /cfg diagnostic endpoints without authentication or with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based on lockout policy configuration and password complexity for the target account.
Refer to VMware advisory VMSA-2021-0016 for more information.
- VMSA-2021-0016 -
www.vmware.com/security/advisories/VMSA-2021-0016.html
CVEs related to QID 376153
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMSA-2021-0016 |
|