CVE-2022-31663: XSS
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-31663?
CVE-2022-31663 is a reflected cross-site scripting (XSS) vulnerability found in VMware Workspace ONE Access, Identity Manager, and vRealize Automation.
What is the severity of CVE-2022-31663?
The severity of CVE-2022-31663 is medium, with a CVSS score of 6.1.
Which software products are affected by CVE-2022-31663?
VMware Identity Manager versions 3.3.4, 3.3.5, and 3.3.6, VMware One Access versions 21.08.0.0 and 21.08.0.1, and VMware Access Connector versions 21.08.0.0, 21.08.0.1, and 22.05 are affected by CVE-2022-31663.
How does CVE-2022-31663 impact users?
CVE-2022-31663 allows a malicious actor with some user interaction to inject JavaScript code in the target user's window.
Where can I find more information about CVE-2022-31663?
More information about CVE-2022-31663 can be found in the VMware Security Advisory VMSA-2022-0021.