Vmware
Vmware Identity Manager: vulnerabilities and CVEs
Vmware Identity Manager has 28 published vulnerabilities, 0 of them in the last 12 months. 8 are rated critical and 3 are listed by CISA as actively exploited.
CVEs28
Last 12 months0
Critical8
Actively exploited3
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22960 | High (7.8) | 36% | ⚠ Active exploitation | Apr 13, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate… |
| CVE-2022-22954 | Critical (9.8) | 100% | ⚠ Active exploitation | Apr 11, 2022 | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection… |
| CVE-2020-4006 | Critical (9.1) | 17% | ⚠ Active exploitation | Nov 23, 2020 | VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability. |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-20884 | Medium (6.1) | 0.35% | — | May 30, 2023 | VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper… |
| CVE-2022-31700 | High (7.2) | 1.1% | — | Dec 14, 2022 | VMware Workspace ONE Access and Identity Manager contain an authenticated remote code execution vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3… |
| CVE-2022-31665 | High (7.2) | 2.4% | — | Aug 5, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution. |
| CVE-2022-31664 | High (7.8) | 0.33% | — | Aug 5, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'. |
| CVE-2022-31663 | Medium (6.1) | 0.67% | — | Aug 5, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction… |
| CVE-2022-31662 | High (7.5) | 1.2% | — | Aug 5, 2022 | VMware Workspace ONE Access, Identity Manager, Connectors and vRealize Automation contain a path traversal vulnerability. A malicious actor with network access may be able to access arbitrary files. |
| CVE-2022-31661 | High (7.8) | 0.33% | — | Aug 5, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two privilege escalation vulnerabilities. A malicious actor with local access can escalate privileges to 'root'. |
| CVE-2022-31660 | High (7.8) | 1.1% | — | Aug 5, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'. |
| CVE-2022-31659 | High (7.2) | 2.9% | — | Aug 5, 2022 | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution. |
| CVE-2022-31658 | High (7.2) | 2.2% | — | Aug 5, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution. |
| CVE-2022-31657 | Critical (9.8) | 1.4% | — | Aug 5, 2022 | VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network access may be able to redirect an authenticated user to an arbitrary domain. |
| CVE-2022-31656 | Critical (9.8) | 24% | — | Aug 5, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain… |
| CVE-2022-22973 | High (7.8) | 2.4% | — | May 20, 2022 | VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'. |
| CVE-2022-22972 | Critical (9.8) | 56% | — | May 20, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain… |
| CVE-2022-22961 | Medium (5.3) | 0.85% | — | Apr 13, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability due to returning excess information. A malicious actor with remote access may leak the hostname of… |
| CVE-2022-22960 | High (7.8) | 36% | ⚠ Active exploitation | Apr 13, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate… |
| CVE-2022-22959 | Medium (4.3) | 0.51% | — | Apr 13, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally… |
| CVE-2022-22958 | High (7.2) | 3.1% | — | Apr 13, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger… |
| CVE-2022-22957 | High (7.2) | 24% | — | Apr 13, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger… |
| CVE-2022-22956 | Critical (9.8) | 50% | — | Apr 13, 2022 | VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any… |
| CVE-2022-22955 | Critical (9.8) | 7.9% | — | Apr 13, 2022 | VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any… |
| CVE-2022-22954 | Critical (9.8) | 100% | ⚠ Active exploitation | Apr 11, 2022 | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection… |
| CVE-2021-22056 | High (7.5) | 1.6% | — | Dec 20, 2021 | VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary… |
| CVE-2021-22003 | High (7.5) | 0.99% | — | Aug 31, 2021 | VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login… |
| CVE-2021-22002 | Critical (9.8) | 1.2% | — | Aug 31, 2021 | VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443… |
| CVE-2020-4006 | Critical (9.1) | 17% | ⚠ Active exploitation | Nov 23, 2020 | VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability. |
| CVE-2016-5334 | Medium (5.3) | 2.1% | — | Dec 29, 2016 | VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF files via unspecified vectors. |
| CVE-2016-5335 | High (7.8) | 0.34% | — | Aug 31, 2016 | VMware Identity Manager 2.x before 2.7 and vRealize Automation 7.0.x before 7.1 allow local users to obtain root access via unspecified vectors. |