← All CVEs

CVE-2022-22972

critical · 9.8

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

9.8
CVSS
56.3%
EPSS (exploit prob.)
99th
EPSS percentile
2022-05-20
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

VendorProductAffected versions
vmwareidentity_manager3.3.3
vmwareidentity_manager3.3.4
vmwareidentity_manager3.3.5
vmwareidentity_manager3.3.6
vmwarevrealize_automation7.6
vmwareworkspace_one_access20.10.0.0
vmwareworkspace_one_access20.10.0.1
vmwareworkspace_one_access21.08.0.0
vmwareworkspace_one_access21.08.0.1
linuxlinux_kernelall versions
vmwarecloud_foundation3.0
vmwarecloud_foundation3.0.1
vmwarecloud_foundation3.0.1.1
vmwarecloud_foundation3.5
vmwarecloud_foundation3.5.1
vmwarecloud_foundation3.7
vmwarecloud_foundation3.7.1
vmwarecloud_foundation3.7.2
vmwarecloud_foundation3.8
vmwarecloud_foundation3.8.1
vmwarecloud_foundation3.9
vmwarecloud_foundation3.9.1
vmwarecloud_foundation3.10
vmwarecloud_foundation3.10.1
vmwarecloud_foundation3.10.1.1
vmwarecloud_foundation3.10.1.2
vmwarecloud_foundation3.10.2.1
vmwarecloud_foundation3.10.2.2
vmwarecloud_foundation3.11
vmwarecloud_foundation3.11.0.1
vmwarecloud_foundation4.0
vmwarecloud_foundation4.0.1
vmwarecloud_foundation4.1
vmwarecloud_foundation4.1.0.1
vmwarecloud_foundation4.2
vmwarecloud_foundation4.2.1
vmwarecloud_foundation4.3
vmwarecloud_foundation4.3.1
vmwarevrealize_suite_lifecycle_manager8.0
vmwarevrealize_suite_lifecycle_manager8.0.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-22972