CVE-2021-22002
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
31/08/2021
Last modified:
09/09/2021
Description
VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443 could tamper with host headers to facilitate access to the /cfg web app, in addition a malicious actor could access /cfg diagnostic endpoints without authentication.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:vmware:identity_manager:3.3.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:identity_manager:3.3.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:identity_manager:3.3.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:identity_manager:3.3.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:workspace_one_access:20.01:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:workspace_one_access:20.10:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:workspace_one_access:20.10.01:*:*:*:*:*:*:* | ||
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:cloud_foundation:4.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:cloud_foundation:4.0.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:cloud_foundation:4.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:cloud_foundation:4.1.0.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:cloud_foundation:4.2.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:vrealize_suite_lifecycle_manager:8.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:vmware:vrealize_suite_lifecycle_manager:8.0.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page