CRITICAL

CVE-2020-4006

Vmware Identity Manager 2020-11-23 CVSS v3.1
CVSS
9.1
KEV

Description

VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.

Summary dbcve.org

VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability that allows attackers to execute arbitrary commands on the underlying system.

Mitigation

Apply vendor-supplied patches or upgrades to the affected VMware identity and access management products immediately, given the critical CVSS 9.1 severity rating.

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

17.3%
Probability of exploitation in next 30 days
97th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE