First published: Wed Apr 13 2022(Updated: )
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts.
Credit: security@vmware.com security@vmware.com security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Cloud Foundation | >=3.0<5.0 | |
VMware Identity Manager | =3.3.3 | |
VMware Identity Manager | =3.3.4 | |
VMware Identity Manager | =3.3.5 | |
VMware Identity Manager | =3.3.6 | |
VMware vRealize Automation | >=8.0<9.0 | |
VMware vRealize Automation | =7.6 | |
Vmware Vrealize Suite Lifecycle Manager | >=8.0<9.0 | |
VMware Workspace ONE Access | =20.10.0.0 | |
VMware Workspace ONE Access | =20.10.0.1 | |
VMware Workspace ONE Access | =21.08.0.0 | |
VMware Workspace ONE Access | =21.08.0.1 | |
Linux Linux kernel | ||
All of | ||
Any of | ||
VMware Cloud Foundation | >=3.0<5.0 | |
VMware Identity Manager | =3.3.3 | |
VMware Identity Manager | =3.3.4 | |
VMware Identity Manager | =3.3.5 | |
VMware Identity Manager | =3.3.6 | |
VMware vRealize Automation | >=8.0<9.0 | |
VMware vRealize Automation | =7.6 | |
Vmware Vrealize Suite Lifecycle Manager | >=8.0<9.0 | |
VMware Workspace ONE Access | =20.10.0.0 | |
VMware Workspace ONE Access | =20.10.0.1 | |
VMware Workspace ONE Access | =21.08.0.0 | |
VMware Workspace ONE Access | =21.08.0.1 | |
Linux Linux kernel | ||
VMware Multiple Products | ||
All of | ||
Any of | ||
>=3.0<5.0 | ||
=3.3.3 | ||
=3.3.4 | ||
=3.3.5 | ||
=3.3.6 | ||
>=8.0<9.0 | ||
=7.6 | ||
>=8.0<9.0 | ||
=20.10.0.0 | ||
=20.10.0.1 | ||
=21.08.0.0 | ||
=21.08.0.1 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22960 is a privilege escalation vulnerability in VMware Workspace ONE Access, Identity Manager, and vRealize Automation.
CVE-2022-22960 has a severity rating of 7.8 (high).
VMware Workspace ONE Access, Identity Manager, and vRealize Automation are affected by CVE-2022-22960.
CVE-2022-22960 allows a malicious actor with local access to escalate privileges to 'root'.
Patch information for CVE-2022-22960 can be found on the VMware website.