cbcvebase.
CVE-2022-22954
published 2022-04-11

CVE-2022-22954: VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with…

PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-05
Exploited in the wild
EPSS
100.00%
100.0th percentile
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

Affected

11 ranges
VendorProductVersion rangeFixed in
vmwarecloud_foundation4.0 – 4.3.1
vmwareidentity_manager
vmwareidentity_manager
vmwareidentity_manager
vmwareidentity_manager
vmwarevrealize_automation
vmwarevrealize_suite_lifecycle_manager8.0 – 8.2
vmwareworkspace_one_access
vmwareworkspace_one_access
vmwareworkspace_one_access
vmwareworkspace_one_access

Detection & IOCsextracted from sources · hover to see the quote

path/etc/passwd
  • CVE-2022-22954 is a server-side template injection (SSTI) vulnerability in VMware Workspace ONE Access; attackers inject Java payloads into expressions using base64-encoded strings passed as arguments to an eval function — detect base64-encoded payloads in HTTP requests targeting Workspace ONE Access endpoints.
  • Exploitation of CVE-2022-22954 was observed at scale within two days of VMware publishing its advisory — monitor for anomalous POST/GET requests to VMware Workspace ONE Access login/authentication endpoints from multiple source IPs.
  • Approximately 10 IPs were observed exploiting CVE-2022-22954 at scale across the internet shortly after disclosure — use threat intelligence feeds (e.g., GreyNoise) to block/alert on known scanning IPs targeting Workspace ONE Access.
  • Iranian state-affiliated group Rocket Kitten was observed exploiting CVE-2022-22954 to gain initial access and deploy penetration testing tools — treat successful exploitation as a potential nation-state intrusion and hunt for post-exploitation pen-test tooling on affected hosts.
  • Multiple threat groups were observed attempting to exploit CVE-2022-22954 — correlate exploitation attempts with threat actor TTPs across diverse groups, not just a single actor.
  • CVE-2022-22954 exploitation was observed in the wild shortly after patch release — prioritize detection on VMware Workspace ONE Access appliances running versions 21.08.0.1, 21.08.0.0, 20.10.0.1, 20.10.0.0 and VMware Identity Manager Appliance 3.3.6, 3.3.5, 3.3.4, 3.3.3.
  • ·VMware notes that vSphere and the connectors for Workspace ONE Access and VMware Identity Manager are NOT affected by these vulnerabilities — scope detection and patching efforts accordingly.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.