cbcvebase.

Vmware Identity Manager vulnerabilities

28 known vulnerabilities affecting vmware/identity_manager.

Total CVEs
28
CISA KEV
3
actively exploited
Public exploits
8
Exploited in wild
7
Severity breakdown
CRITICAL8HIGH15MEDIUM5

Vulnerabilities

Page 2 of 2
CVE-2022-31661P3HIGHCVSS 7.8v3.3.4v3.3.5+1 more2022-08-05
CVE-2022-31661 [HIGH] CVE-2022-31661: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two privilege escalati VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two privilege escalation vulnerabilities. A malicious actor with local access can escalate privileges to 'root'.
nvd
CVE-2022-31664P3HIGHCVSS 7.8v3.3.4v3.3.5+1 more2022-08-05
CVE-2022-31664 [HIGH] CVE-2022-31664: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.
nvd
CVE-2016-5335P4HIGHCVSS 7.8≥ 2.0, < 2.72016-08-31
CVE-2016-5335 [HIGH] CVE-2016-5335: VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to obtain root access via unspecified vectors.
nvd
CVE-2016-5334P4MEDIUMCVSS 5.3≥ 2.0, < 2.7.12016-12-29
CVE-2016-5334 [MEDIUM] CWE-668 CVE-2016-5334: VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attac VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF files via unspecified vectors.
nvd
CVE-2023-20884P4MEDIUMCVSS 6.1v3.3.6v3.3.72023-05-30
CVE-2023-20884 [MEDIUM] CWE-601 CVE-2023-20884: VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.
nvd
CVE-2022-22961P4MEDIUMCVSS 5.3v3.3.3v3.3.4+2 more2022-04-13
CVE-2022-22961 [MEDIUM] CWE-200 CVE-2022-22961: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclos VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of the target system. Successful exploitation of this issue can lead to targeting victims.
nvd
CVE-2022-31663P4MEDIUMCVSS 6.1v3.3.4v3.3.5+1 more2022-08-05
CVE-2022-31663 [MEDIUM] CWE-79 CVE-2022-31663: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.
nvd
CVE-2022-22959P4MEDIUMCVSS 4.3v3.3.3v3.3.4+2 more2022-04-13
CVE-2022-22959 [MEDIUM] CWE-352 CVE-2022-22959: VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request f VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally validate a malicious JDBC URI.
nvd
Vmware Identity Manager vulnerabilities | cvebase