QID 730594

Date Published: 2022-08-11

QID 730594: VMware Identity Manager (vIDM) and Workspace ONE Access Multiple Vulnerabilities (VMSA-2022-0021) (Unauthenticated Check)

VMware released VMSA-2022-0021, a critical advisory addressing security vulnerabilities found and resolved in VMware Workspace ONE Access (Access) and VMware Identity Manager (vIDM)

Affected Versions:
VMware Workspace ONE Access (Access) versions 21.08.0.1 and 21.08.0.0
VMware Identity Manager (vIDM) versions 3.3.6, 3.3.5, and 3.3.4
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of VMware Identity Manager and VMware Workspace ONE Access by sending a crafted payload to the SAAS/t/_/;/auth/login/embeddedauthbroker/callback endpoint.

Successful exploitation of these vulnerabilities may result in authentication bypass and admin Remote Code Execution.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    VMware has released patches for these vulnerabilities.

    Refer to VMware advisory VMSA-2022-0021 and VMware KB VM_KB_ 89096 for more information.

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2022-0021 URL Logo www.vmware.com/security/advisories/VMSA-2022-0021.html