CVE-2022-31657: Critical severity vmware workspace one access and identity manager vulnerability
VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network access may be able to redirect an authenticated user to an arbitrary domain.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-31657?
CVE-2022-31657 is a URL injection vulnerability in VMware Workspace ONE Access and Identity Manager.
How severe is CVE-2022-31657?
CVE-2022-31657 has a severity rating of 9.8 (critical).
Which software versions are affected by CVE-2022-31657?
CVE-2022-31657 affects VMware Identity Manager versions 3.3.4, 3.3.5, and 3.3.6, VMware One Access versions 21.08.0.0 and 21.08.0.1, and VMware Access Connector versions 21.08.0.0, 21.08.0.1, and 22.05.
How can CVE-2022-31657 be exploited?
CVE-2022-31657 can be exploited by a malicious actor with network access who can redirect an authenticated user to any domain.
Where can I find more information about CVE-2022-31657?
More information about CVE-2022-31657 can be found at the official VMware security advisory: https://www.vmware.com/security/advisories/VMSA-2022-0021.html