CVE-2022-22954
Description
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.
Summary dbcve.org
VMware Workspace ONE Access and Identity Manager are affected by a server-side template injection vulnerability that allows a remote, unauthenticated attacker with network access to the affected service to execute arbitrary code on the underlying host. Because the injection occurs server-side during request processing, exploitation does not require valid credentials and yields full remote code execution in the context of the vulnerable application.
Mitigation
Apply the vendor-issued patches for VMware Workspace ONE Access and Identity Manager as soon as possible, and restrict network access to the management interfaces of these appliances (e.g., firewall, network segmentation, VPN-only access) until patching is complete.