CVE-2022-22954: VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.
Other sources
VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this VMware Workspace ONE Access and Identity Manager vulnerability?
The vulnerability ID is CVE-2022-22954.
What is the severity rating of CVE-2022-22954?
The severity rating of CVE-2022-22954 is critical with a score of 9.8.
What is the affected software for CVE-2022-22954?
The affected software includes VMware Workspace ONE Access and Identity Manager, VMware Identity Manager, VMware vRealize Automation, and VMware Workspace ONE Access.
How is the vulnerability CVE-2022-22954 exploited?
The vulnerability is exploited through server-side template injection, which allows for remote code execution.
Where can I find more information about CVE-2022-22954?
You can find more information about CVE-2022-22954 on the following websites: [Packet Storm Security](http://packetstormsecurity.com/files/166935/VMware-Workspace-ONE-Access-Template-Injection-Command-Execution.html) and [VMware Security Advisories](https://www.vmware.com/security/advisories/VMSA-2022-0011.html).