CVE-2022-31659: SQL Injection
Published Aug 5, 2022
·Updated
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.
Affected Software
14 affected components
VMware Identity Manager=3.3.4
VMware Identity Manager=3.3.5
VMware Identity Manager=3.3.6
VMware ONE Access=21.08.0.0
VMware ONE Access=21.08.0.1
Linux Linux kernel
VMware Access Connector=22.05
VMware Access Connector=22.08.0.0
VMware Access Connector=22.08.0.1
VMware Identity Manager Connector=3.3.4
VMware Identity Manager Connector=3.3.5
VMware Identity Manager Connector=3.3.6
VMware Identity Manager Connector=19.03.0.1
Microsoft Windows
Remediation
Event History
Aug 5, 2022
CVE Published
via MITRE·03:06 PM
Data Sourced
via MITRE·03:06 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-31659.
2
What is the severity of CVE-2022-31659?
The severity of CVE-2022-31659 is high with a severity value of 7.2.
3
Which software is affected by CVE-2022-31659?
VMware Identity Manager versions 3.3.4, 3.3.5, and 3.3.6 as well as Vmware One Access versions 21.08.0.0 and 21.08.0.1 are affected by CVE-2022-31659.
4
How can a malicious actor exploit the vulnerability?
A malicious actor with administrator and network access can trigger a remote code execution.
5
Where can I find more information about CVE-2022-31659?
You can find more information about CVE-2022-31659 on the VMware website: https://www.vmware.com/security/advisories/VMSA-2022-0021.html