CVE-2022-31665: High severity vmware workspace one access and identity manager vulnerability
Published Aug 5, 2022
·Updated
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution.
Affected Software
11 affected components
VMware Identity Manager=3.3.4
VMware Identity Manager=3.3.5
VMware Identity Manager=3.3.6
VMware ONE Access=21.08.0.0
VMware ONE Access=21.08.0.1
Linux Linux kernel
VMware Identity Manager Connector=3.3.4
VMware Identity Manager Connector=3.3.5
VMware Identity Manager Connector=3.3.6
VMware Identity Manager Connector=19.03.0.1
Microsoft Windows
Remediation
Event History
Aug 5, 2022
CVE Published
via MITRE·03:06 PM
Data Sourced
via MITRE·03:06 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-31665.
2
What is the severity of CVE-2022-31665?
The severity of CVE-2022-31665 is high with a score of 7.2.
3
Which software versions are affected by CVE-2022-31665?
VMware Identity Manager versions 3.3.4, 3.3.5, and 3.3.6, VMware One Access versions 21.08.0.0 and 21.08.0.1 are affected by CVE-2022-31665.
4
How can a malicious actor exploit CVE-2022-31665?
A malicious actor with administrator and network access can trigger a remote code execution.
5
Where can I find more information about CVE-2022-31665?
You can find more information about CVE-2022-31665 in the VMware security advisory VMSA-2022-0021.