QID 377877
Date Published: 2023-02-07
QID 377877: VMware Identity Manager (vIDM) and Workspace ONE Access Authenticated Remote Code Execution (RCE) Vulnerability (VMSA-2022-0032)
VMware Workspace ONE Access and Identity Manager contain an authenticated remote code execution vulnerability. A malicious actor with network access may be able to obtain system information due to an unauthenticated endpoint. Successful exploitation of this issue can lead to targeting victims.
Affected Versions:
VMware Workspace ONE Access (Access) versions 21.08.0.1, 21.08.0.0
VMware Identity Manager (vIDM) versions: 3.3.6
QID Detection Logic (Authenticated):
This QID checks for vulnerable versions of VMware Identity Manager and VMware Workspace ONE Access with build version on the target and checks for the presence of patch.
Successful exploitation of this vulnerability could lead to a malicious actor with network access may be able to obtain system information due to an unauthenticated endpoint.
Refer to VMware advisory VMSA-2022-0032 and VMware KB VM_KB_ 90399 for more information.
- VMSA-2022-0032 -
www.vmware.com/security/advisories/VMSA-2022-0032.html
CVEs related to QID 377877
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMSA-2022-0032 |
|