CVE-2022-22961: Infoleak
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the target system. Successful exploitation of this issue can lead to targeting victims.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-22961?
CVE-2022-22961 is an information disclosure vulnerability found in VMware Workspace ONE Access, Identity Manager, and vRealize Automation.
How does CVE-2022-22961 affect VMware Workspace ONE Access, Identity Manager, and vRealize Automation?
CVE-2022-22961 allows a remote attacker to leak the hostname of the target system, leading to potential targeting of victims.
What is the severity of CVE-2022-22961?
CVE-2022-22961 has a severity rating of medium, with a score of 5.3.
Which versions of VMware Workspace ONE Access and Identity Manager are affected by CVE-2022-22961?
Versions 3.3.3, 3.3.4, 3.3.5, 3.3.6, 20.10.0.0, 20.10.0.1, 21.08.0.0, and 21.08.0.1 of VMware Workspace ONE Access and Identity Manager are affected by CVE-2022-22961.
How can I mitigate the CVE-2022-22961 vulnerability?
To mitigate CVE-2022-22961, it is recommended to apply the necessary patches and updates provided by VMware.