cbcvebase.
CVE-2022-22957
published 2022-04-13

CVE-2022-22957: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A…

high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EXPLOIT
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution.

Affected

12 ranges
VendorProductVersion rangeFixed in
vmwarecloud_foundation>= 3.0 < 5.05.0
vmwareidentity_manager
vmwareidentity_manager
vmwareidentity_manager
vmwareidentity_manager
vmwarevrealize_automation
vmwarevrealize_automation>= 8.0 < 9.09.0
vmwarevrealize_suite_lifecycle_manager>= 8.0 < 9.09.0
vmwareworkspace_one_access
vmwareworkspace_one_access
vmwareworkspace_one_access
vmwareworkspace_one_access

CVSS provenance

nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vulncheck7.2HIGH