9.8

CVE-2022-22972

Warning

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

Data is provided by the National Vulnerability Database (NVD)
VMwareIdentity Manager Version3.3.3
   LinuxLinux Kernel Version-
VMwareIdentity Manager Version3.3.4
   LinuxLinux Kernel Version-
VMwareIdentity Manager Version3.3.5
   LinuxLinux Kernel Version-
VMwareIdentity Manager Version3.3.6
   LinuxLinux Kernel Version-
VMwareVrealize Automation Version7.6
   LinuxLinux Kernel Version-
VMwareWorkspace One Access Version20.10.0.0
   LinuxLinux Kernel Version-
VMwareWorkspace One Access Version20.10.0.1
   LinuxLinux Kernel Version-
VMwareWorkspace One Access Version21.08.0.0
   LinuxLinux Kernel Version-
VMwareWorkspace One Access Version21.08.0.1
   LinuxLinux Kernel Version-
VMwareCloud Foundation Version3.0
VMwareCloud Foundation Version3.0.1
VMwareCloud Foundation Version3.0.1.1
VMwareCloud Foundation Version3.5
VMwareCloud Foundation Version3.5.1
VMwareCloud Foundation Version3.7
VMwareCloud Foundation Version3.7.1
VMwareCloud Foundation Version3.7.2
VMwareCloud Foundation Version3.8
VMwareCloud Foundation Version3.8.1
VMwareCloud Foundation Version3.9
VMwareCloud Foundation Version3.9.1
VMwareCloud Foundation Version3.10
VMwareCloud Foundation Version3.10.1
VMwareCloud Foundation Version3.10.1.1
VMwareCloud Foundation Version3.10.1.2
VMwareCloud Foundation Version3.10.2.1
VMwareCloud Foundation Version3.10.2.2
VMwareCloud Foundation Version3.11
VMwareCloud Foundation Version3.11.0.1
VMwareCloud Foundation Version4.0
VMwareCloud Foundation Version4.0.1
VMwareCloud Foundation Version4.1
VMwareCloud Foundation Version4.1.0.1
VMwareCloud Foundation Version4.2
VMwareCloud Foundation Version4.2.1
VMwareCloud Foundation Version4.3
VMwareCloud Foundation Version4.3.1
VMwareVrealize Suite Lifecycle Manager Version8.2 Updatepatch1
VMwareVrealize Suite Lifecycle Manager Version8.2 Updatepatch2
VMwareVrealize Suite Lifecycle Manager Version8.2 Updatepatch3
VMwareVrealize Suite Lifecycle Manager Version8.3 Updatepatch1
VMwareVrealize Suite Lifecycle Manager Version8.3 Updatepatch2
VMwareVrealize Suite Lifecycle Manager Version8.3 Updatepatch3
VMwareVrealize Suite Lifecycle Manager Version8.4 Updatepatch1
VMwareVrealize Suite Lifecycle Manager Version8.4.1 Updatepatch1
VMwareVrealize Suite Lifecycle Manager Version8.4.1 Updatepatch2
VMwareVrealize Suite Lifecycle Manager Version8.4.1 Updatepatch3
VMwareVrealize Suite Lifecycle Manager Version8.6 Updatepatch1
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 93.72% 0.998
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P