CVE-2021-22057: High severity vmware workspace one access and identity manager vulnerability
VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 contain an authentication bypass vulnerability. A malicious actor, who has successfully provided first-factor authentication, may be able to obtain second-factor authentication provided by VMware Verify.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-22057?
CVE-2021-22057 is an authentication bypass vulnerability found in VMware Workspace ONE Access.
Which versions of VMware Workspace ONE Access are affected?
VMware Workspace ONE Access versions 20.10, 20.10.0.1, 21.08, and 21.08.0.1 are affected.
What is the severity of CVE-2021-22057?
The severity of CVE-2021-22057 is rated as high with a CVSS score of 8.8.
What is the impact of CVE-2021-22057?
A successful attacker who has provided first-factor authentication can bypass second-factor authentication provided by VMware Verify.
Is there a fix available for CVE-2021-22057?
Yes, VMware has released security advisories and patches to address the authentication bypass vulnerability. Please refer to the official VMware advisory for more details and apply the necessary updates.