CVE-2023-20884
published 2023-05-30CVE-2023-20884: VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect…
PriorityP426medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.35%
27.0th percentile
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | identity_manager | — | — |
| vmware | identity_manager | — | — |
| vmware | workspace_one_access | 21.0.8.0 – 22.09.1.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Workspace ONE Access and Identity Manager update addresses an Insecure Redirect Vulnerability. (CVE-2023-20884)
vendor_vmware·2023-05-30·CVSS 6.1
CVE-2023-20884 [MEDIUM] VMware Workspace ONE Access and Identity Manager update addresses an Insecure Redirect Vulnerability. (CVE-2023-20884)
VMSA-2023-0011: VMware Workspace ONE Access and Identity Manager update addresses an Insecure Redirect Vulnerability. (CVE-2023-20884)
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 6.1.
CVEs: CVE-2023-20884
Affected products: VMware Cloud Foundation, VMware Identity Manager, VMware Workspace ONE
GHSA
GHSA-mhgf-hv55-f778: VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability
ghsa_unreviewed·2023-07-06
CVE-2023-20884 [MEDIUM] CWE-601 GHSA-mhgf-hv55-f778: VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-05-30
Published