CVE-2022-31656: Critical severity vmware workspace one access and identity manager vulnerability
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-31656?
CVE-2022-31656 is a critical vulnerability that affects VMware Workspace ONE Access, Identity Manager, and vRealize Automation, allowing for an authentication bypass.
Which software versions are affected by CVE-2022-31656?
CVE-2022-31656 affects VMware Identity Manager versions 3.3.4, 3.3.5, and 3.3.6, as well as VMware One Access versions 21.08.0.0 and 21.08.0.1.
What is the severity of CVE-2022-31656?
CVE-2022-31656 is classified as critical with a severity value of 9.8.
How can an attacker exploit CVE-2022-31656?
A malicious actor with network access to the UI can exploit CVE-2022-31656 to gain administrative access without the need to authenticate.
Where can I find more information about CVE-2022-31656?
You can find more information about CVE-2022-31656 in the VMware Security Advisory VMSA-2022-0021.