PT-2021-3249 · Vmware · Vmware Workspace One Uem

Lauritz Holtmann

+1

·

Published

2021-05-11

·

Updated

2022-06-05

·

CVE-2021-21990

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions VMware Workspace One versions 20.1.0.0 through 20.1.0.31 VMware Workspace One versions 20.3.0.0 through 20.3.0.22 VMware Workspace One versions 20.4.0.0 through 20.4.0.20 VMware Workspace One versions 20.5.0.0 through 20.5.0.45 VMware Workspace One versions 20.6.0.0 through 20.6.0.18 VMware Workspace One versions 20.7.0.0 through 20.7.0.13 VMware Workspace One versions 20.8.0.0 through 20.8.0.27 VMware Workspace One versions 20.10.0.0 through 20.10.0.15 VMware Workspace One versions 20.11.0.0 through 20.11.0.26 VMware Workspace One versions 21.1.0.0 through 21.1.0.13 VMware Workspace One versions 21.2.0.0 through 21.2.0.7
Description The issue exists due to insufficient protection of the web page structure in VMware Workspace One, allowing a remote attacker to impact the confidentiality and integrity of protected information. This is a result of a cross-site scripting vulnerability in the VMware Workspace One UEM console, where the console does not validate incoming requests during device enrollment, leading to the rendering of unsanitized input on the user device in response.
Recommendations For versions 20.1.0.0 through 20.1.0.31, update to version 20.1.0.32 or later. For versions 20.3.0.0 through 20.3.0.22, update to version 20.3.0.23 or later. For versions 20.4.0.0 through 20.4.0.20, update to version 20.4.0.21 or later. For versions 20.5.0.0 through 20.5.0.45, update to version 20.5.0.46 or later. For versions 20.6.0.0 through 20.6.0.18, update to version 20.6.0.19 or later. For versions 20.7.0.0 through 20.7.0.13, update to version 20.7.0.14 or later. For versions 20.8.0.0 through 20.8.0.27, update to version 20.8.0.28 or later. For versions 20.10.0.0 through 20.10.0.15, update to version 20.10.0.16 or later. For versions 20.11.0.0 through 20.11.0.26, update to version 20.11.0.27 or later. For versions 21.1.0.0 through 21.1.0.13, update to version 21.1.0.14 or later. For versions 21.2.0.0 through 21.2.0.7, update to version 21.2.0.8 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02969
CVE-2021-21990

Affected Products

Vmware Workspace One Uem