- EPSS 94.44%
- Veröffentlicht 11.04.2022 20:15:19
- Zuletzt bearbeitet 30.10.2025 20:04:37
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code ex...
CVE-2021-22057
- EPSS 0.15%
- Veröffentlicht 20.12.2021 21:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:30
VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 contain an authentication bypass vulnerability. A malicious actor, who has successfully provided first-factor authentication, may be able to obtain second-factor authentication provided by VMwar...
CVE-2021-22056
- EPSS 0.66%
- Veröffentlicht 20.12.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 05:49:30
VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full respons...
CVE-2021-22002
- EPSS 0.46%
- Veröffentlicht 31.08.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:25
VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443 could tamper with host headers ...
CVE-2021-22003
- EPSS 0.42%
- Veröffentlicht 31.08.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 05:49:25
VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be pract...