QID 730447

Date Published: 2022-05-02

QID 730447: VMware Identity Manager (vIDM) and Workspace ONE Access Remote Code Execution (RCE) Vulnerability (Unauthenticated Check)

VMware released VMSA-2022-0011, a critical advisory addressing security vulnerabilities found and resolved in VMware Workspace ONE Access, VMware Identity Manager (vIDM), vRealize Lifecycle Manager, vRealize Automation, and VMware Cloud Foundation products. Of which, this QID launches a specially crafted payload onto VMware Workspace ONE Access and VMware Identity Manager (vIDM) to find the RCE vulnerability

Affected Versions:
VMware Workspace ONE Access (Access) versions 21.08.0.1, 21.08.0.0, 21.10.0.1, and 21.10.0.0
VMware Identity Manager (vIDM) versions: 3.3.3, 3.3.4, 3.3.5, and 3.3.6

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable VMware Workspace ONE Access and VMware Identity Manager (vIDM) by sending a specially crafted payload.

Successful exploitation of this vulnerability could lead to:
A malicious actor with network access can trigger a server-side template injection that may result in remote code execution in VMware Workspace ONE Access.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    VMware has released patches for these vulnerabilities.

    Refer to VMware advisory VMSA-2022-0011 and VMware KB VM_KB_ 88099 for more information.

    Workaround:
    Refer to VMware KB VM_KB_ 88098 for more information.

    CVEs related to QID 730447

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2022-0011 URL Logo www.vmware.com/security/advisories/VMSA-2022-0011.html