CVE-2022-22956
published 2022-04-13CVE-2022-22956: VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may…
PriorityP191critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
50.69%
98.8th percentile
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | identity_manager | — | — |
| vmware | identity_manager | — | — |
| vmware | identity_manager | — | — |
| vmware | identity_manager | — | — |
| vmware | vrealize_automation | — | — |
| vmware | vrealize_automation | >= 8.0 < 9.0 | 9.0 |
| vmware | workspace_one_access | — | — |
| vmware | workspace_one_access | — | — |
| vmware | workspace_one_access | — | — |
| vmware | workspace_one_access | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS VMware Workspace ONE Access OAuth2TokenResourceController ACS Authentication Bypass (CVE-2022-22956)"; flow:established,to_server; http.uri; content:"/SAAS/API/1.0/REST/oauth2/generateActivationToken/Service__OAuth2Client"; fast_pattern; http.method; content:"POST"; reference:url,srcincite.io/blog/2022/08/11/i-am-whoever-i-say-i-am-infiltrating-vmware-workspace-one-access-using-a-0-click-exploit.html; reference:cve,2022-22956; classtype:web-application-attack; sid:2065404; rev:1; metadata:affected_product VMware, attack_target Server, tls_state TLSDecrypt, created_at 2025_10_27, cve CVE_2022_22956, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence High, signature_severity Major, tag Exploit, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2025_10_27, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
- →The exploit chain begins with an unauthenticated POST to the OAuth2TokenResourceController ACS endpoint to generate an activation token for the built-in 'Service__OAuth2Client' OAuth2 client, which should never be reachable without authentication. ↗
- →A three-step HTTP sequence is the fingerprint of exploitation: (1) POST to /SAAS/API/1.0/REST/oauth2/generateActivationToken/Service__OAuth2Client returning an activationToken, (2) POST to /SAAS/API/1.0/REST/oauth2/activate returning client_id and client_secret, (3) POST to /SAAS/auth/oauthtoken with grant_type=client_credentials to obtain an access_token. ↗
- →The Snort/ET rule uses fast_pattern on the URI string '/SAAS/API/1.0/REST/oauth2/generateActivationToken/Service__OAuth2Client' combined with HTTP method POST to detect the initial bypass request. ↗
- →The Nuclei template requires max-request: 3 and uses a chained flow, meaning detection of all three sequential requests to the SAAS OAuth2 endpoints from the same source IP is a strong indicator of active exploitation. ↗
- ·The exploit chain for CVE-2022-22956 is designed to be chained with CVE-2022-22957 (JDBC injection RCE in DBConnectionCheckController); detection of the auth bypass alone does not confirm full RCE, but the bypass is a prerequisite. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-54hw-pp59-j3rc: VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework
ghsa_unreviewed·2022-04-14·CVSS 9.8
CVE-2022-22956 [CRITICAL] CWE-287 GHSA-54hw-pp59-j3rc: VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
GHSA
GHSA-vv47-c6mc-7w69: VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework
ghsa_unreviewed·2022-04-14·CVSS 9.8
CVE-2022-22955 [CRITICAL] CWE-287 GHSA-vv47-c6mc-7w69: VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
VulnCheck
VMware Workspace ONE Access and Identity Manager Improper Authentication
vulncheck·2022·CVSS 9.8
CVE-2022-22956 [CRITICAL] VMware Workspace ONE Access and Identity Manager Improper Authentication
VMware Workspace ONE Access and Identity Manager Improper Authentication
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
Affected: VMware Workspace ONE Access and Identity Manager
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://hs-8813571.f.hubspotemail.net/hubfs/8813571/PERISCOPE_VULNINTEL_20250903.pdf; https://app.crowdsec.net/cti/cve-explorer/CVE-2022-22956; https://dashboard.shadowserver.org/statistics/honeypot/vulne
VMware
VMware Workspace ONE Access, Identity Manager and vRealize Automation updates address multiple vulnerabilities.
vendor_vmware·2022-04-06·CVSS 9.8
CVE-2022-22954 [CRITICAL] VMware Workspace ONE Access, Identity Manager and vRealize Automation updates address multiple vulnerabilities.
VMSA-2022-0011: VMware Workspace ONE Access, Identity Manager and vRealize Automation updates address multiple vulnerabilities.
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
CVEs: CVE-2022-22954, CVE-2022-22955, CVE-2022-22956, CVE-2022-22957, CVE-2022-22958, CVE-2022-22959, CVE-2022-22960, CVE-2022-22961
Affected products: VMware Aria, VMware Cloud Foundation, VMware Identity Manager, VMware Workspace ONE, VMware vRealize
Suricata
ET WEB_SPECIFIC_APPS VMware Workspace ONE Access OAuth2TokenResourceController ACS Authentication Bypass (CVE-2022-22956)
suricata·2025-10-27·CVSS 9.8
CVE-2022-22956 [CRITICAL] ET WEB_SPECIFIC_APPS VMware Workspace ONE Access OAuth2TokenResourceController ACS Authentication Bypass (CVE-2022-22956)
ET WEB_SPECIFIC_APPS VMware Workspace ONE Access OAuth2TokenResourceController ACS Authentication Bypass (CVE-2022-22956)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS VMware Workspace ONE Access OAuth2TokenResourceController ACS Authentication Bypass (CVE-2022-22956)"; flow:established,to_server; http.uri; content:"/SAAS/API/1.0/REST/oauth2/generateActivationToken/Service__OAuth2Client"; fast_pattern; http.method; content:"POST"; reference:url,srcincite.io/blog/2022/08/11/i-am-whoever-i-say-i-am-infiltrating-vmware-workspace-one-access-using-a-0-click-exploit.html; reference:cve,2022-22956; classtype:web-application-attack; sid:2065404; rev:1; metadata:affected_product VMware, attack_target Server, tls_state TLSDecrypt, created_at 2025_10_27, cve CVE_2022_22956, de
Metasploit
VMware Workspace ONE Access VMSA-2022-0011 exploit chain
metasploit·CVSS 9.8
CVE-2022-22956 [CRITICAL] VMware Workspace ONE Access VMSA-2022-0011 exploit chain
VMware Workspace ONE Access VMSA-2022-0011 exploit chain
This module combines two vulnerabilities in order achieve remote code execution in the context of the `horizon` user. The first vulnerability CVE-2022-22956 is an authentication bypass in OAuth2TokenResourceController ACS which allows a remote, unauthenticated attacker to bypass the authentication mechanism and execute any operation. The second vulnerability CVE-2022-22957 is a JDBC injection RCE specifically in the DBConnectionCheckController class's dbCheck method which allows an attacker to deserialize arbitrary Java objects which can allow remote code execution.
Nuclei
VMware Workspace ONE Access - Authentication Bypass
nuclei·CVSS 9.8
CVE-2022-22956 [CRITICAL] VMware Workspace ONE Access - Authentication Bypass
VMware Workspace ONE Access - Authentication Bypass
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
Template:
id: CVE-2022-22956
info:
name: VMware Workspace ONE Access - Authentication Bypass
author: daffainfo
severity: critical
description: |
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
impact: |
Attackers can bypass authentica
Unit42
Threat Brief: VMware Vulnerabilities Exploited in the Wild (CVE-2022-22954 and Others)
blogs_unit42·2022-05-20·CVSS 9.8
CVE-2022-22954 [CRITICAL] Threat Brief: VMware Vulnerabilities Exploited in the Wild (CVE-2022-22954 and Others)
Threat Research Center
High Profile Threats
Vulnerabilities
## Threat Brief: VMware Vulnerabilities Exploited in the Wild (CVE-2022-22954 and Others)
Ruchna Nigam
Published: May 20, 2022
High Profile Threats
Vulnerabilities
CVE-2022-22954
CVE-2022-22960
CVE-2022-22972
CVE-2022-22973
VMware
## Executive Summary
On April 6, 2022, VMware published a security advisory mentioning eight vulnerabilities, including CVE-2022-22954 and CVE-2022-22960 impacting their products VMware Workspace ONE Access, Identity Manager and vRealize Automation. On April 13, they updated their advisory with information that CVE-2022-22954 is being exploited in the wild.
Multiple writeups detailing exploitation scenarios for the aforementioned two vulnerabilities were published in the last week of A
Unit42
Threat Brief: VMware Vulnerabilities Exploited in the Wild (CVE-2022-22954 and Others)
blogs_unit42·2022-05-20·CVSS 9.8
CVE-2022-22954 [CRITICAL] Threat Brief: VMware Vulnerabilities Exploited in the Wild (CVE-2022-22954 and Others)
## Executive Summary
On April 6, 2022, VMware published a security advisory mentioning eight vulnerabilities, including CVE-2022-22954 and CVE-2022-22960 impacting their products VMware Workspace ONE Access, Identity Manager and vRealize Automation. On April 13, they updated their advisory with information that CVE-2022-22954 is being exploited in the wild.
Multiple writeups detailing exploitation scenarios for the aforementioned two vulnerabilities were published in the last week of April, finally followed by a CISA Alert on May 18. The CISA Alert also calls out CVE-2022-22972 and CVE-2022-22973 – published on the same day and affecting the same products – as being highly likely to be exploited.
Unit 42 has observed numerous instances of CVE-2022-22954 being exploited in the wild. In t
Tenable
VMware Patches Multiple Vulnerabilities in Workspace ONE, Identity and Lifecycle Manager and vRealize (VMSA-2022-0011)
blogs_tenable·2022-04-07
VMware Patches Multiple Vulnerabilities in Workspace ONE, Identity and Lifecycle Manager and vRealize (VMSA-2022-0011)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://packetstormsecurity.com/files/171918/Mware-Workspace-ONE-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/171918/VMware-Workspace-ONE-Remote-Code-Execution.htmlhttps://www.vmware.com/security/advisories/VMSA-2022-0011.htmlhttp://packetstormsecurity.com/files/171918/Mware-Workspace-ONE-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/171918/VMware-Workspace-ONE-Remote-Code-Execution.htmlhttps://www.vmware.com/security/advisories/VMSA-2022-0011.html
2022-04-13
Published
Exploited in the wild