CVE-2022-22958Incorrect Permission Assignment in Vmware Cloud Foundation

Severity
7.2HIGHNVD
EPSS
3.0%
top 13.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 13
Latest updateApr 14

Description

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages5 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-h783-2f78-cqf2: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-2292022-04-14
CVEList
CVE-2022-22958: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-2292022-04-13

📋Vendor Advisories

1
VMware
VMware Workspace ONE Access, Identity Manager and vRealize Automation updates address multiple vulnerabilities.2022-04-06
CVE-2022-22958 — Incorrect Permission Assignment | cvebase