QID 378548

Date Published: 2023-08-09

QID 378548: VMware Identity Manager (vIDM) and Workspace ONE Access Insecure Redirect Vulnerability (VMSA-2023-0011)

An insecure redirect vulnerability in Workspace ONE Access and Identity Manager was privately reported to VMware. Updates are available to address this vulnerability in affected VMware products.

Affected Versions:
VMware Workspace ONE Access (Access) versions 22.09.0.0, 22.09.1.0
VMware Identity Manager (vIDM) versions: 3.3.6,3.3.7

QID Detection Logic (Authenticated):
This QID checks for vulnerable versions of VMware Identity Manager and VMware Workspace ONE Access with build version on the target and checks for the presence of patch.

An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    VMware has released patches for these vulnerabilities.

    Refer to VMware advisory VMSA-2023-0011 and VMware KB VM_KB_ 92512 for more information.

    CVEs related to QID 378548

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2023-0011 URL Logo www.vmware.com/security/advisories/VMSA-2023-0011.html