CVE-2022-22955: Critical severity vmware workspace one access and identity manager vulnerability
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-22955?
CVE-2022-22955 is a vulnerability in the OAuth2 ACS framework of VMware Workspace ONE Access that allows authentication bypass.
How does CVE-2022-22955 affect VMware Workspace ONE Access?
CVE-2022-22955 exposes endpoints in the authentication framework, enabling a malicious actor to bypass authentication and execute any operation.
What is the severity of CVE-2022-22955?
CVE-2022-22955 has a severity rating of 9.8 (Critical).
Which versions of VMware Workspace ONE Access are affected by CVE-2022-22955?
CVE-2022-22955 affects VMware Workspace ONE Access versions 3.3.3, 3.3.4, 3.3.5, 3.3.6, 20.10.0.0, 20.10.0.1, 21.08.0.0, and 21.08.0.1.
Where can I find more information about CVE-2022-22955?
More information about CVE-2022-22955 can be found on the VMware Security Advisories page: [https://www.vmware.com/security/advisories/VMSA-2022-0011.html](https://www.vmware.com/security/advisories/VMSA-2022-0011.html)