CVE-2021-22003: High severity vmware workspace one access and identity manager vulnerability
VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based on lockout policy configuration and password complexity for the target account.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-22003?
CVE-2021-22003 is a vulnerability in VMware Workspace ONE Access and Identity Manager that unintentionally provides a login interface on port 7443.
What is the severity of CVE-2021-22003?
CVE-2021-22003 has a severity level of 7.5 (high).
Which software is affected by CVE-2021-22003?
CVE-2021-22003 affects VMware Identity Manager versions 3.3.2, 3.3.3, 3.3.4, and 3.3.5, as well as VMware Workspace ONE Access versions 20.01, 20.10, and 20.10.01.
What can a malicious actor do with CVE-2021-22003?
A malicious actor with network access to port 7443 can attempt user enumeration or brute force the login endpoint.
How can I fix CVE-2021-22003?
To fix CVE-2021-22003, apply the necessary security updates provided by VMware.