CVE-2022-22957: High severity vmware vcenter server and cloud foundation vulnerability
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What are the vulnerabilities identified in this advisory?
The vulnerabilities identified in this advisory are CVE-2022-22957 and CVE-2022-22958.
What is the severity rating for CVE-2022-22957?
The severity rating for CVE-2022-22957 is 7.2 (High).
What is the affected software for CVE-2022-22957?
The affected software for CVE-2022-22957 includes VMware Workspace ONE Access, Identity Manager, and vRealize Automation.
How can a malicious actor exploit CVE-2022-22957?
A malicious actor with administrative access can exploit CVE-2022-22957 by triggering deserialization of untrusted data through a malicious JDBC URI.
Where can I find additional information about CVE-2022-22957?
You can find additional information about CVE-2022-22957 in the VMware security advisory VMSA-2022-0011.