CVE-2022-22955
- EPSS 0.43%
- Veröffentlicht 13.04.2022 18:15:12
- Zuletzt bearbeitet 21.11.2024 06:47:40
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in t...
- EPSS 94.44%
- Veröffentlicht 11.04.2022 20:15:19
- Zuletzt bearbeitet 12.03.2025 20:01:47
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code ex...
CVE-2021-22056
- EPSS 0.89%
- Veröffentlicht 20.12.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 05:49:30
VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full respons...
CVE-2021-22003
- EPSS 0.36%
- Veröffentlicht 31.08.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:25
VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be pract...
CVE-2021-22002
- EPSS 0.4%
- Veröffentlicht 31.08.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:25
VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443 could tamper with host headers ...
CVE-2020-4006
- EPSS 15.59%
- Veröffentlicht 23.11.2020 22:15:12
- Zuletzt bearbeitet 02.04.2025 20:22:15
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
CVE-2016-5334
- EPSS 0.23%
- Veröffentlicht 29.12.2016 09:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF files via unspecified vectors.
CVE-2016-5335
- EPSS 0.03%
- Veröffentlicht 31.08.2016 01:59:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to obtain root access via unspecified vectors.