CVE-2022-22958 — Incorrect Permission Assignment in Vmware Cloud Foundation
Severity
7.2HIGHNVD
EPSS
3.0%
top 13.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 13
Latest updateApr 14
Description
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9
Affected Packages5 packages
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-h783-2f78-cqf2: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-229↗2022-04-14
CVEList▶
CVE-2022-22958: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-229↗2022-04-13
📋Vendor Advisories
1VMware▶
VMware Workspace ONE Access, Identity Manager and vRealize Automation updates address multiple vulnerabilities.↗2022-04-06