CVE-2022-22959: CSRF
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally validate a malicious JDBC URI.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-22959?
CVE-2022-22959 is a cross site request forgery vulnerability in VMware Workspace ONE Access, Identity Manager, and vRealize Automation.
Which software are affected by CVE-2022-22959?
VMware Cloud Foundation, VMware Identity Manager, VMware vRealize Automation, and VMware Workspace ONE Access are affected by CVE-2022-22959.
What is the severity of CVE-2022-22959?
CVE-2022-22959 has a severity rating of 4.3 (medium).
What is the CWE ID of CVE-2022-22959?
CVE-2022-22959 is associated with CWE-352 (Cross-Site Request Forgery).
How can I fix CVE-2022-22959?
VMware has released security advisories and patches for the affected software. It is recommended to apply the necessary updates to address the vulnerability.