CVE-2021-22002: Critical severity vmware workspace one access and identity manager vulnerability
VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443 could tamper with host headers to facilitate access to the /cfg web app, in addition a malicious actor could access /cfg diagnostic endpoints without authentication.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-22002?
CVE-2021-22002 is a vulnerability in VMware Workspace ONE Access and Identity Manager that allows the /cfg web app and diagnostic endpoints on port 8443 to be accessed via port 443 using a custom host header.
Which software versions are affected by CVE-2021-22002?
CVE-2021-22002 affects VMware Identity Manager versions 3.3.2, 3.3.3, 3.3.4, and 3.3.5, as well as VMware Workspace ONE Access versions 20.01, 20.10, and 20.10.01.
How severe is CVE-2021-22002?
CVE-2021-22002 has a severity rating of 9.8 (Critical).
How can an attacker exploit CVE-2021-22002?
An attacker with network access to port 443 could tamper with host headers to gain unauthorized access to the /cfg web app in VMware Workspace ONE Access and Identity Manager.
Is the Linux Linux kernel vulnerable to CVE-2021-22002?
No, the Linux Linux kernel is not vulnerable to CVE-2021-22002.