QID 376184

Date Published: 2021-12-16

QID 376184: VMware Identity Manager (vIDM) and Workspace ONE Access Apache Log4j Remote Code Execution (RCE) Vulnerability (VMSA-2021-0028)

VMware Workspace One Access contain a Command Injection Vulnerability in the administrative configurator.
VMware Identity Manager contain a Command Injection Vulnerability in the administrative configurator.

Affected Versions:
VMware Identity Manager (vIDM) 3.3.3
VMware Identity Manager (vIDM) 3.3.4
VMware Identity Manager (vIDM) 3.3.5

VMware Workspace ONE Access (Access) 21.08.0.0
VMware Workspace ONE Access (Access) 21.08.0.1
VMware Workspace ONE Access (Access) 20.10.0.0
VMware Workspace ONE Access (Access) 20.10.0.1

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of VMware Identity Manager and VMware Workspace ONE Access (Access) with build version on the target.
Note: Patch for this vulnerability is not available yet. We are unable to check the workaround through detection, hence this QID is a Potential Vulnerability.

A malicious actor with network access to an impacted VMware product may exploit this issue to gain full control of the target system.

  • CVSS V3 rated as Critical - 10 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    Currently, there is no resolution. Please check VMSA-2021-0028 for updates. Workaround:

    Refer to KB87081 for more information.

    CVEs related to QID 376184

    Software Advisories
    Advisory ID Software Component Link