QID 730508

Date Published: 2022-05-26

QID 730508: VMware Identity Manager (vIDM) and Workspace ONE Access Authentication Bypass Vulnerability (VMSA-2022-0014) (Unauthenticated Check)

VMware released VMSA-2022-0014, a critical advisory addressing security vulnerabilities found and resolved in VMware Workspace ONE Access (Access), VMware Identity Manager (vIDM), vRealize Lifecycle Manager, vRealize Automation, and VMware Cloud Foundation products.

Affected Versions:
VMware Workspace ONE Access (Access) versions 21.08.0.1, 21.08.0.0, 21.10.0.1, and 21.10.0.0
VMware Identity Manager (vIDM) versions 3.3.6, 3.3.5, 3.3.4, and 3.3.3
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable VMware Identity Manager and VMware Workspace ONE Access by sending a crafted payload to the target server.

Successful exploitation of the vulnerability could allow a remote attacker to login as local user.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    VMware has released patch

    Refer to VMware advisory VMSA-2022-0014 and VMware KB VM_KB_ 88438 for more information.

    Workaround:

    Refer to VMware KB KB88433 for more information.

    CVEs related to QID 730508

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2022-0014 URL Logo www.vmware.com/security/advisories/VMSA-2022-0014.html