First published: Fri Aug 05 2022(Updated: )
VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network access may be able to redirect an authenticated user to an arbitrary domain.
Credit: security@vmware.com security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Identity Manager | =3.3.4 | |
VMware Identity Manager | =3.3.5 | |
VMware Identity Manager | =3.3.6 | |
Vmware One Access | =21.08.0.0 | |
Vmware One Access | =21.08.0.1 | |
Linux Linux kernel | ||
Vmware Access Connector | =21.08.0.0 | |
Vmware Access Connector | =21.08.0.1 | |
Vmware Access Connector | =22.05 | |
Vmware Identity Manager Connector | =3.3.4 | |
Vmware Identity Manager Connector | =3.3.5 | |
Vmware Identity Manager Connector | =3.3.6 | |
Vmware Identity Manager Connector | =19.03.0.1 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31657 is a URL injection vulnerability in VMware Workspace ONE Access and Identity Manager.
CVE-2022-31657 has a severity rating of 9.8 (critical).
CVE-2022-31657 affects VMware Identity Manager versions 3.3.4, 3.3.5, and 3.3.6, VMware One Access versions 21.08.0.0 and 21.08.0.1, and VMware Access Connector versions 21.08.0.0, 21.08.0.1, and 22.05.
CVE-2022-31657 can be exploited by a malicious actor with network access who can redirect an authenticated user to any domain.
More information about CVE-2022-31657 can be found at the official VMware security advisory: https://www.vmware.com/security/advisories/VMSA-2022-0021.html