CVE-2022-22972: Critical severity vmware workspace one access and identity manager vulnerability
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22972?
CVE-2022-22972 has been classified as a high severity vulnerability due to the potential for unauthorized administrative access.
How do I fix CVE-2022-22972?
To fix CVE-2022-22972, apply the relevant patches provided by VMware for affected versions of Workspace ONE Access, Identity Manager, and vRealize Automation.
Who is affected by CVE-2022-22972?
Local domain users with network access to the UI are at risk from CVE-2022-22972, enabling possible administrative access without authentication.
What products are affected by CVE-2022-22972?
CVE-2022-22972 affects VMware Workspace ONE Access, Identity Manager, and vRealize Automation across several specific versions.
What kind of vulnerability is CVE-2022-22972 classified as?
CVE-2022-22972 is classified as an authentication bypass vulnerability.