CVE-2022-22958
Published Apr 13, 2022
Last updated a year ago
Overview
- Description
- VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which may result in remote code execution.
- Source
- security@vmware.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.2
- Impact score
- 5.9
- Exploitability score
- 1.2
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 6.5
- Impact score
- 6.4
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-502
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5071E0B4-FE4B-4525-BAF6-3900D9C8D48D", "versionEndExcluding": "5.0", "versionStartIncluding": "3.0" }, { "criteria": "cpe:2.3:a:vmware:identity_manager:3.3.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "97D98937-489B-4AA5-B99E-9AB639C582CA" }, { "criteria": "cpe:2.3:a:vmware:identity_manager:3.3.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0E93CB5E-CB4A-474A-9901-2E098928C489" }, { "criteria": "cpe:2.3:a:vmware:identity_manager:3.3.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2A215A7D-F644-41DE-AB4E-69145DA48F9F" }, { "criteria": "cpe:2.3:a:vmware:identity_manager:3.3.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5EBB8190-2101-4EE5-844E-B46E7FB78FD7" }, { "criteria": "cpe:2.3:a:vmware:vrealize_automation:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "370EF5F6-77E2-4EF7-9148-9DA5C52E50F5", "versionEndExcluding": "9.0", "versionStartIncluding": "8.0" }, { "criteria": "cpe:2.3:a:vmware:vrealize_automation:7.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "471BB5AF-3744-45FE-937D-BBEC421035EB" }, { "criteria": "cpe:2.3:a:vmware:vrealize_suite_lifecycle_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FC19367B-D2F8-4966-BE2F-12700C9337EC", "versionEndExcluding": "9.0", "versionStartIncluding": "8.0" }, { "criteria": "cpe:2.3:a:vmware:workspace_one_access:20.10.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "639F6029-DE62-49BD-A767-C5D499389C37" }, { "criteria": "cpe:2.3:a:vmware:workspace_one_access:20.10.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "88AD029C-7707-4F1E-BE7F-2DE27D384538" }, { "criteria": "cpe:2.3:a:vmware:workspace_one_access:21.08.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "57375AD7-8042-472F-B49E-653C77EAFA48" }, { "criteria": "cpe:2.3:a:vmware:workspace_one_access:21.08.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AC3DC465-1FA7-4F5B-9A9A-12F8FB4CE146" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "703AF700-7A70-47E2-BC3A-7FD03B3CA9C1" } ], "operator": "OR" } ], "operator": "AND" } ]