First published: Wed Apr 13 2022(Updated: )
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the target system. Successful exploitation of this issue can lead to targeting victims.
Credit: security@vmware.com security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Cloud Foundation | >=3.0<5.0 | |
VMware Identity Manager | =3.3.3 | |
VMware Identity Manager | =3.3.4 | |
VMware Identity Manager | =3.3.5 | |
VMware Identity Manager | =3.3.6 | |
VMware vRealize Automation | >=8.0<9.0 | |
VMware vRealize Automation | =7.6 | |
Vmware Vrealize Suite Lifecycle Manager | >=8.0<9.0 | |
VMware Workspace ONE Access | =20.10.0.0 | |
VMware Workspace ONE Access | =20.10.0.1 | |
VMware Workspace ONE Access | =21.08.0.0 | |
VMware Workspace ONE Access | =21.08.0.1 | |
Linux Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22961 is an information disclosure vulnerability found in VMware Workspace ONE Access, Identity Manager, and vRealize Automation.
CVE-2022-22961 allows a remote attacker to leak the hostname of the target system, leading to potential targeting of victims.
CVE-2022-22961 has a severity rating of medium, with a score of 5.3.
Versions 3.3.3, 3.3.4, 3.3.5, 3.3.6, 20.10.0.0, 20.10.0.1, 21.08.0.0, and 21.08.0.1 of VMware Workspace ONE Access and Identity Manager are affected by CVE-2022-22961.
To mitigate CVE-2022-22961, it is recommended to apply the necessary patches and updates provided by VMware.