CVE-2022-31689: Critical severity vmware workspace one assist vulnerability
Published Nov 9, 2022
·Updated
VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token.
Affected Software
1 affected component
VMware Workspace ONE Assist<22.10
Remediation
Event History
Nov 9, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-31689?
CVE-2022-31689 has a medium severity rating due to the potential for session fixation attacks.
2
How do I fix CVE-2022-31689?
To fix CVE-2022-31689, upgrade to VMware Workspace ONE Assist version 22.10 or later.
3
What kind of attack does CVE-2022-31689 allow?
CVE-2022-31689 allows a malicious actor to perform session fixation attacks by using a valid session token.
4
Which versions of VMware Workspace ONE Assist are affected by CVE-2022-31689?
CVE-2022-31689 affects versions of VMware Workspace ONE Assist prior to 22.10.
5
What is session fixation in the context of CVE-2022-31689?
Session fixation is a type of attack where an attacker tricks a user into using a specific session ID, which the attacker can then hijack.