CVE-2022-22958: High severity vmware vcenter server and cloud foundation vulnerability
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What are the vulnerabilities associated with CVE-2022-22958?
CVE-2022-22958 is associated with two remote code execution vulnerabilities: CVE-2022-22957 and CVE-2022-22958.
Which software are affected by CVE-2022-22958?
VMware Workspace ONE Access, Identity Manager, and vRealize Automation are affected by CVE-2022-22958.
What is the severity rating of CVE-2022-22958?
The severity rating of CVE-2022-22958 is high, with a severity value of 7.2.
How can a malicious actor exploit CVE-2022-22958?
A malicious actor with administrative access can trigger deserialization of untrusted data through a malicious JDBC URI, resulting in remote code execution.
Where can I find more information about CVE-2022-22958?
You can find more information about CVE-2022-22958 on the VMware Security Advisories page: [VMware Security Advisories](https://www.vmware.com/security/advisories/VMSA-2022-0011.html).