CRITICAL

CVE-2022-22954

Vmware Identity Manager 2022-04-11 CVSS v3.1
CVSS
9.8
KEV

Description

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

Summary dbcve.org

VMware Workspace ONE Access and Identity Manager are affected by a server-side template injection vulnerability that allows a remote, unauthenticated attacker with network access to the affected service to execute arbitrary code on the underlying host. Because the injection occurs server-side during request processing, exploitation does not require valid credentials and yields full remote code execution in the context of the vulnerable application.

Mitigation

Apply the vendor-issued patches for VMware Workspace ONE Access and Identity Manager as soon as possible, and restrict network access to the management interfaces of these appliances (e.g., firewall, network segmentation, VPN-only access) until patching is complete.

Proof of Concept

Weakness (CWE)

CWE-94 Code Injection

EPSS Score

100%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE