First published: Tue May 30 2023(Updated: )
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Identity Manager | =3.3.6 | |
VMware Identity Manager | =3.3.7 | |
Linux Linux kernel | ||
VMware Workspace ONE Access | >=21.0.8.0<=22.09.1.0 | |
VMware Cloud Foundation | ||
Vmware Identity Manager Connector | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-20884.
The severity of CVE-2023-20884 is medium.
The affected software by CVE-2023-20884 is VMware Workspace ONE Access and VMware Identity Manager.
CVE-2023-20884 can allow an unauthenticated malicious actor to redirect a victim to an attacker controlled domain, leading to sensitive information disclosure.
Yes, patches and fixes for CVE-2023-20884 are available. Please refer to the vendor's security advisory for more information.