CVE-2022-22955
published 2022-04-13CVE-2022-22955: VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may…
PriorityP273critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
8.09%
94.1th percentile
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | identity_manager | — | — |
| vmware | identity_manager | — | — |
| vmware | identity_manager | — | — |
| vmware | identity_manager | — | — |
| vmware | vrealize_automation | — | — |
| vmware | vrealize_automation | >= 8.0 < 9.0 | 9.0 |
| vmware | workspace_one_access | — | — |
| vmware | workspace_one_access | — | — |
| vmware | workspace_one_access | — | — |
| vmware | workspace_one_access | — | — |
Detection & IOCsextracted from sources · hover to see the quote
url/SAAS/API/1.0/REST/oauth2/generateActivationToken/Service__OAuth2Client
url/SAAS/API/1.0/REST/oauth2/activate
url/SAAS/auth/oauthtoken
otherhttp.favicon.hash:-1250474341
othericon_hash=-1250474341
- →Step 1 of exploit chain: Unauthenticated POST to the generateActivationToken endpoint for 'Service__OAuth2Client' returns HTTP 200 with JSON body containing 'activationToken' and '_links' fields — no credentials required.
- →Step 2 of exploit chain: The extracted activationToken is POSTed to /SAAS/API/1.0/REST/oauth2/activate; a successful bypass returns HTTP 200 JSON with 'client_id' and 'client_secret'.
- →Step 3 of exploit chain: The obtained client_id and client_secret are used in a client_credentials grant to /SAAS/auth/oauthtoken, yielding a valid access_token — confirming full authentication bypass.
- →Detect exploitation by monitoring for sequential unauthenticated POST requests to all three endpoints: /SAAS/API/1.0/REST/oauth2/generateActivationToken/*, /SAAS/API/1.0/REST/oauth2/activate, and /SAAS/auth/oauthtoken from the same source IP.
- →Content-Type header 'application/x-www-form-urlencoded' with Content-Length: 0 on the generateActivationToken POST is a strong indicator of exploit attempt — no body is sent.
- →Identify exposed VMware Workspace ONE Access instances via Shodan favicon hash -1250474341 or FOFA icon_hash=-1250474341.
- ·The vulnerability affects the OAuth2 ACS framework's exposed endpoints; the exploit chain requires exactly three sequential requests — detection logic should correlate all three steps rather than alerting on individual requests to reduce false positives. ↗
- ·The Nuclei template targets CVE-2022-22956 (the sibling bypass) but the exploit chain and endpoints are shared with CVE-2022-22955; detections covering these endpoints apply to both CVEs. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-54hw-pp59-j3rc: VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework
ghsa_unreviewed·2022-04-14·CVSS 9.8
CVE-2022-22956 [CRITICAL] CWE-287 GHSA-54hw-pp59-j3rc: VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
GHSA
GHSA-vv47-c6mc-7w69: VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework
ghsa_unreviewed·2022-04-14·CVSS 9.8
CVE-2022-22955 [CRITICAL] CWE-287 GHSA-vv47-c6mc-7w69: VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
VulnCheck
VMware Workspace ONE Access and Identity Manager Improper Authentication
vulncheck·2022·CVSS 9.8
CVE-2022-22956 [CRITICAL] VMware Workspace ONE Access and Identity Manager Improper Authentication
VMware Workspace ONE Access and Identity Manager Improper Authentication
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
Affected: VMware Workspace ONE Access and Identity Manager
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://hs-8813571.f.hubspotemail.net/hubfs/8813571/PERISCOPE_VULNINTEL_20250903.pdf; https://app.crowdsec.net/cti/cve-explorer/CVE-2022-22956; https://dashboard.shadowserver.org/statistics/honeypot/vulne
VMware
VMware Workspace ONE Access, Identity Manager and vRealize Automation updates address multiple vulnerabilities.
vendor_vmware·2022-04-06·CVSS 9.8
CVE-2022-22954 [CRITICAL] VMware Workspace ONE Access, Identity Manager and vRealize Automation updates address multiple vulnerabilities.
VMSA-2022-0011: VMware Workspace ONE Access, Identity Manager and vRealize Automation updates address multiple vulnerabilities.
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
CVEs: CVE-2022-22954, CVE-2022-22955, CVE-2022-22956, CVE-2022-22957, CVE-2022-22958, CVE-2022-22959, CVE-2022-22960, CVE-2022-22961
Affected products: VMware Aria, VMware Cloud Foundation, VMware Identity Manager, VMware Workspace ONE, VMware vRealize
No detection rules found.
Nuclei
VMware Workspace ONE Access - Authentication Bypass
nuclei·CVSS 9.8
CVE-2022-22956 [CRITICAL] VMware Workspace ONE Access - Authentication Bypass
VMware Workspace ONE Access - Authentication Bypass
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
Template:
id: CVE-2022-22956
info:
name: VMware Workspace ONE Access - Authentication Bypass
author: daffainfo
severity: critical
description: |
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
impact: |
Attackers can bypass authentica
Unit42
Threat Brief: VMware Vulnerabilities Exploited in the Wild (CVE-2022-22954 and Others)
blogs_unit42·2022-05-20·CVSS 9.8
CVE-2022-22954 [CRITICAL] Threat Brief: VMware Vulnerabilities Exploited in the Wild (CVE-2022-22954 and Others)
Threat Research Center
High Profile Threats
Vulnerabilities
## Threat Brief: VMware Vulnerabilities Exploited in the Wild (CVE-2022-22954 and Others)
Ruchna Nigam
Published: May 20, 2022
High Profile Threats
Vulnerabilities
CVE-2022-22954
CVE-2022-22960
CVE-2022-22972
CVE-2022-22973
VMware
## Executive Summary
On April 6, 2022, VMware published a security advisory mentioning eight vulnerabilities, including CVE-2022-22954 and CVE-2022-22960 impacting their products VMware Workspace ONE Access, Identity Manager and vRealize Automation. On April 13, they updated their advisory with information that CVE-2022-22954 is being exploited in the wild.
Multiple writeups detailing exploitation scenarios for the aforementioned two vulnerabilities were published in the last week of A
Unit42
Threat Brief: VMware Vulnerabilities Exploited in the Wild (CVE-2022-22954 and Others)
blogs_unit42·2022-05-20·CVSS 9.8
CVE-2022-22954 [CRITICAL] Threat Brief: VMware Vulnerabilities Exploited in the Wild (CVE-2022-22954 and Others)
## Executive Summary
On April 6, 2022, VMware published a security advisory mentioning eight vulnerabilities, including CVE-2022-22954 and CVE-2022-22960 impacting their products VMware Workspace ONE Access, Identity Manager and vRealize Automation. On April 13, they updated their advisory with information that CVE-2022-22954 is being exploited in the wild.
Multiple writeups detailing exploitation scenarios for the aforementioned two vulnerabilities were published in the last week of April, finally followed by a CISA Alert on May 18. The CISA Alert also calls out CVE-2022-22972 and CVE-2022-22973 – published on the same day and affecting the same products – as being highly likely to be exploited.
Unit 42 has observed numerous instances of CVE-2022-22954 being exploited in the wild. In t
Tenable
VMware Patches Multiple Vulnerabilities in Workspace ONE, Identity and Lifecycle Manager and vRealize (VMSA-2022-0011)
blogs_tenable·2022-04-07
VMware Patches Multiple Vulnerabilities in Workspace ONE, Identity and Lifecycle Manager and vRealize (VMSA-2022-0011)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
2022-04-13
Published