VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Identity_manager | Vmware | 3.3.3 (including) | 3.3.3 (including) |
Identity_manager | Vmware | 3.3.4 (including) | 3.3.4 (including) |
Identity_manager | Vmware | 3.3.5 (including) | 3.3.5 (including) |
Identity_manager | Vmware | 3.3.6 (including) | 3.3.6 (including) |
Vrealize_automation | Vmware | 8.0 (including) | 9.0 (excluding) |
Vrealize_automation | Vmware | 7.6 (including) | 7.6 (including) |
Workspace_one_access | Vmware | 20.10.0.0 (including) | 20.10.0.0 (including) |
Workspace_one_access | Vmware | 20.10.0.1 (including) | 20.10.0.1 (including) |
Workspace_one_access | Vmware | 21.08.0.0 (including) | 21.08.0.0 (including) |
Workspace_one_access | Vmware | 21.08.0.1 (including) | 21.08.0.1 (including) |