QID 730508
Date Published: 2022-05-26
QID 730508: VMware Identity Manager (vIDM) and Workspace ONE Access Authentication Bypass Vulnerability (VMSA-2022-0014) (Unauthenticated Check)
VMware released VMSA-2022-0014, a critical advisory addressing security vulnerabilities found and resolved in VMware Workspace ONE Access (Access), VMware Identity Manager (vIDM), vRealize Lifecycle Manager, vRealize Automation, and VMware Cloud Foundation products.
Affected Versions:
VMware Workspace ONE Access (Access) versions 21.08.0.1, 21.08.0.0, 21.10.0.1, and 21.10.0.0
VMware Identity Manager (vIDM) versions 3.3.6, 3.3.5, 3.3.4, and 3.3.3
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable VMware Identity Manager and VMware Workspace ONE Access by sending a crafted payload to the target server.
Successful exploitation of the vulnerability could allow a remote attacker to login as local user.
Refer to VMware advisory VMSA-2022-0014 and VMware KB VM_KB_ 88438 for more information.
Workaround:
Refer to VMware KB KB88433 for more information.
- VMSA-2022-0014 -
www.vmware.com/security/advisories/VMSA-2022-0014.html
CVEs related to QID 730508
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMSA-2022-0014 |
|