QID 377754
Date Published: 2022-11-09
QID 377754: VMware Workspace ONE Assist Multiple Security Vulnerabilities (VMSA-2022-0028)
VMware Workspace ONE Assist allows VMware Workspace ONE UEM administrators to remotely access and troubleshoot devices in real time while respecting end-user privacy.
CVE-2022-31685: VMware Workspace ONE Assist contains an Authentication Bypass vulnerability.
CVE-2022-31686: VMware Workspace ONE Assist contains a Broken Authentication Method vulnerability.
CVE-2022-31687: VMware Workspace ONE Assist contains a Broken Access Control vulnerability.
CVE-2022-31688: VMware Workspace ONE Assist contains a reflected cross-site scripting (XSS) vulnerability.
CVE-2022-31689: VMware Workspace ONE Assist contains a session fixation vulnerability due to improper handling of session tokens.
Affected Versions:
VMware Workspace ONE Assist versions from 21.x prior to 22.10
QID Detection Logic (Authenticated):
Windows: This QID checks for vulnerable versions of Workspace ONE Assist exe using registry "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Workspace ONE Assist".
Successful exploitation of these vulnerabilities may allow an attacker with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.
Refer to VMware advisory VMSA-2022-0028 for more information.
- VMSA-2022-0028 -
www.vmware.com/security/advisories/VMSA-2022-0028.html
CVEs related to QID 377754
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMSA-2022-0028 |
|