Vmware
Vmware ONE Access: vulnerabilities and CVEs
Vmware ONE Access has 11 published vulnerabilities, 0 of them in the last 12 months. 3 are rated critical and 1 are listed by CISA as actively exploited.
CVEs11
Last 12 months0
Critical3
Actively exploited1
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-4006 | Critical (9.1) | 17% | ⚠ Active exploitation | Nov 23, 2020 | VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability. |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-31665 | High (7.2) | 2.4% | — | Aug 5, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution. |
| CVE-2022-31664 | High (7.8) | 0.33% | — | Aug 5, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'. |
| CVE-2022-31663 | Medium (6.1) | 0.67% | — | Aug 5, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction… |
| CVE-2022-31662 | High (7.5) | 1.2% | — | Aug 5, 2022 | VMware Workspace ONE Access, Identity Manager, Connectors and vRealize Automation contain a path traversal vulnerability. A malicious actor with network access may be able to access arbitrary files. |
| CVE-2022-31661 | High (7.8) | 0.33% | — | Aug 5, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two privilege escalation vulnerabilities. A malicious actor with local access can escalate privileges to 'root'. |
| CVE-2022-31660 | High (7.8) | 1.1% | — | Aug 5, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'. |
| CVE-2022-31659 | High (7.2) | 2.9% | — | Aug 5, 2022 | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution. |
| CVE-2022-31658 | High (7.2) | 2.2% | — | Aug 5, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution. |
| CVE-2022-31657 | Critical (9.8) | 1.4% | — | Aug 5, 2022 | VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network access may be able to redirect an authenticated user to an arbitrary domain. |
| CVE-2022-31656 | Critical (9.8) | 24% | — | Aug 5, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain… |
| CVE-2020-4006 | Critical (9.1) | 17% | ⚠ Active exploitation | Nov 23, 2020 | VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.