CVE-2021-22056: SSRF
VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2021-22056.
What is the severity of CVE-2021-22056?
The severity of CVE-2021-22056 is high with a severity value of 7.5.
Which products are affected by CVE-2021-22056?
VMware Workspace ONE Access versions 21.08, 20.10.0.1, and 20.10, as well as Identity Manager versions 3.3.5, 3.3.4, and 3.3.3 are affected by CVE-2021-22056.
What is the impact of CVE-2021-22056?
A malicious actor with network access could exploit CVE-2021-22056 to make HTTP requests to arbitrary origins and read the full response.
Are there any additional references for CVE-2021-22056?
Yes, you can find more information about CVE-2021-22056 at the following link: [VMware Security Advisory VMSA-2021-0030](https://www.vmware.com/security/advisories/VMSA-2021-0030.html)