QID 376617

Date Published: 2022-05-20

QID 376617: VMware Identity Manager (vIDM) and Workspace ONE Access Multiple Vulnerabilities (VMSA-2022-0014)

VMware released VMSA-2022-0014, a critical advisory addressing security vulnerabilities found and resolved in VMware Workspace ONE Access (Access), VMware Identity Manager (vIDM), vRealize Lifecycle Manager, vRealize Automation, and VMware Cloud Foundation products.

Affected Versions:
VMware Workspace ONE Access (Access) versions 21.08.0.1, 21.08.0.0, 21.10.0.1, and 21.10.0.0
VMware Identity Manager (vIDM) versions 3.3.6, 3.3.5, 3.3.4, and 3.3.3
QID Detection Logic (Authenticated):
This QID checks for vulnerable versions of VMware Identity Manager and VMware Workspace ONE Access with build version on the target.

Successful exploitation of these vulnerabilities could lead to an authentication bypass vulnerability affecting local domain users and a malicious actor with local access can escalate privileges to 'root'.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    VMware has released patches for these vulnerabilities.

    Refer to VMware advisory VMSA-2022-0014 and VMware KB VM_KB_ 88438 for more information.

    Workaround:

    Refer to VMware KB KB88433 for more information.

    CVEs related to QID 376617

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2022-0014 URL Logo www.vmware.com/security/advisories/VMSA-2022-0014.html