CVE-2022-22972
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/05/2022
Last modified:
08/08/2023
Description
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:vmware:identity_manager:3.3.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:vmware:identity_manager:3.3.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:vmware:identity_manager:3.3.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:vmware:identity_manager:3.3.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:vmware:vrealize_automation:7.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:vmware:workspace_one_access:20.10.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:vmware:workspace_one_access:20.10.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:vmware:workspace_one_access:21.08.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:vmware:workspace_one_access:21.08.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:linux:linux_kernel:-:*:*:*:*:*:*:* | ||
| cpe:2.3:a:vmware:cloud_foundation:3.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:vmware:cloud_foundation:3.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:vmware:cloud_foundation:3.0.1.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:vmware:cloud_foundation:3.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:vmware:cloud_foundation:3.5.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



