cbcvebase.
CVE-2022-22957
published 2022-04-13

CVE-2022-22957: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A…

PriorityP278high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
23.08%
97.5th percentile
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution.

Affected

12 ranges
VendorProductVersion rangeFixed in
vmwarecloud_foundation>= 3.0 < 5.05.0
vmwareidentity_manager
vmwareidentity_manager
vmwareidentity_manager
vmwareidentity_manager
vmwarevrealize_automation
vmwarevrealize_automation>= 8.0 < 9.09.0
vmwarevrealize_suite_lifecycle_manager>= 8.0 < 9.09.0
vmwareworkspace_one_access
vmwareworkspace_one_access
vmwareworkspace_one_access
vmwareworkspace_one_access

Detection & IOCsextracted from sources · hover to see the quote

url/SAAS/t/<tenant>/jersey/manager/api/system/dbCheck
othermalicious JDBC URI triggering deserialization of untrusted data
  • Monitor HTTP requests targeting the DBConnectionCheckController endpoint (dbCheck method) for JDBC URI parameters containing unexpected class references or serialized Java object payloads.
  • Inspect JDBC URI values supplied to the dbCheck API for non-standard drivers or class names (e.g., jdbc:h2:, jdbc:hsqldb:, or other drivers capable of triggering Java deserialization gadget chains).
  • Monitor for process execution anomalies under the 'horizon' user on VMware Workspace ONE Access / Identity Manager / vRealize Automation hosts, as successful exploitation results in RCE in that user context.
  • ·CVE-2022-22957 requires the attacker to already have administrative access (or chain it with CVE-2022-22956 auth bypass). Detection rules should account for both authenticated admin abuse and unauthenticated chained exploitation scenarios.
  • ·Affected products include VMware Workspace ONE Access, Identity Manager, and vRealize Automation — ensure detection coverage spans all three products, not just one.

CVSS provenance

nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vulncheck7.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.