First published: Wed Nov 09 2022(Updated: )
VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Workspace ONE Assist | <22.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31687 is considered a critical vulnerability due to its potential for unauthorized administrative access.
To fix CVE-2022-31687, update VMware Workspace ONE Assist to version 22.10 or later.
Organizations using VMware Workspace ONE Assist versions prior to 22.10 are affected by CVE-2022-31687.
CVE-2022-31687 is caused by a broken access control vulnerability that allows unauthenticated administrative access.
Yes, CVE-2022-31687 can be exploited remotely by a malicious actor with network access to Workspace ONE Assist.