CVE-2022-31662: Path Traversal
VMware Workspace ONE Access, Identity Manager, Connectors and vRealize Automation contain a path traversal vulnerability. A malicious actor with network access may be able to access arbitrary files.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-31662?
CVE-2022-31662 is a path traversal vulnerability in VMware Workspace ONE Access, Identity Manager, Connectors, and vRealize Automation.
What is the severity of CVE-2022-31662?
CVE-2022-31662 has a severity value of 7.5, which is considered high.
Which software versions are affected by CVE-2022-31662?
CVE-2022-31662 affects VMware Identity Manager versions 3.3.4, 3.3.5, and 3.3.6, as well as Vmware One Access versions 21.08.0.0 and 21.08.0.1.
How can a malicious actor exploit CVE-2022-31662?
A malicious actor with network access may be able to exploit CVE-2022-31662 to access arbitrary files.
Where can I find more information about CVE-2022-31662?
You can find more information about CVE-2022-31662 in the VMware Security Advisory VMSA-2022-0021: https://www.vmware.com/security/advisories/VMSA-2022-0021.html