Vmware Identity Manager vulnerabilities
28 known vulnerabilities affecting vmware/identity_manager.
Total CVEs
28
CISA KEV
3
actively exploited
Public exploits
8
Exploited in wild
7
Severity breakdown
CRITICAL8HIGH15MEDIUM5
Vulnerabilities
Page 2 of 2
CVE-2022-31661P3HIGHCVSS 7.8v3.3.4v3.3.5+1 more2022-08-05
CVE-2022-31661 [HIGH] CVE-2022-31661: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two privilege escalati
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two privilege escalation vulnerabilities. A malicious actor with local access can escalate privileges to 'root'.
nvd
CVE-2022-31664P3HIGHCVSS 7.8v3.3.4v3.3.5+1 more2022-08-05
CVE-2022-31664 [HIGH] CVE-2022-31664: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.
nvd
CVE-2016-5335P4HIGHCVSS 7.8≥ 2.0, < 2.72016-08-31
CVE-2016-5335 [HIGH] CVE-2016-5335: VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to
VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to obtain root access via unspecified vectors.
nvd
CVE-2016-5334P4MEDIUMCVSS 5.3≥ 2.0, < 2.7.12016-12-29
CVE-2016-5334 [MEDIUM] CWE-668 CVE-2016-5334: VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attac
VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF files via unspecified vectors.
nvd
CVE-2023-20884P4MEDIUMCVSS 6.1v3.3.6v3.3.72023-05-30
CVE-2023-20884 [MEDIUM] CWE-601 CVE-2023-20884: VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability.
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.
nvd
CVE-2022-22961P4MEDIUMCVSS 5.3v3.3.3v3.3.4+2 more2022-04-13
CVE-2022-22961 [MEDIUM] CWE-200 CVE-2022-22961: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclos
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the target system. Successful exploitation of this issue can lead to targeting victims.
nvd
CVE-2022-31663P4MEDIUMCVSS 6.1v3.3.4v3.3.5+1 more2022-08-05
CVE-2022-31663 [MEDIUM] CWE-79 CVE-2022-31663: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.
nvd
CVE-2022-22959P4MEDIUMCVSS 4.3v3.3.3v3.3.4+2 more2022-04-13
CVE-2022-22959 [MEDIUM] CWE-352 CVE-2022-22959: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request f
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally validate a malicious JDBC URI.
nvd
← Previous2 / 2