QID 730684
QID 730684: VMware Identity Manager (vIDM) and Workspace ONE Access Authenticated Remote Code Execution (RCE) Vulnerability (VMSA-2022-0032) (Unauthenticated Check)
VMware Workspace ONE Access and Identity Manager contain an authenticated remote code execution vulnerability. A malicious actor with network access may be able to obtain system information due to an unauthenticated endpoint. Successful exploitation of this issue can lead to targeting victims.
Affected Versions:
VMware Workspace ONE Access (Access) versions 21.08.0.1, 21.08.0.0
VMware Identity Manager (vIDM) versions: 3.3.6
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable VMware Workspace ONE Access and VMware Identity Manager (vIDM) by sending a specially crafted payload.
Successful exploitation of this vulnerability could lead to a malicious actor with network access may be able to obtain system information due to an unauthenticated endpoint.
Refer to VMware advisory VMSA-2022-0032 and VMware KB VM_KB_ 90399 for more information.
- VMSA-2022-0032 -
www.vmware.com/security/advisories/VMSA-2022-0032.html
CVEs related to QID 730684
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMSA-2022-0032 |
|