PT-2021-6847 · Vmware · Vmware Workspace One Access+1

Keiran Sampson

+1

·

Published

2021-12-16

·

Updated

2022-01-19

·

CVE-2021-22056

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions VMware Workspace ONE Access versions 20.10 through 21.08 VMware Identity Manager versions 3.3.3 through 3.3.5
Description The issue is related to insufficient validation of incoming requests, allowing a remote attacker to impact the confidentiality and integrity of protected information using specially crafted HTTP requests. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response. This is a Server-Side Request Forgery (SSRF) vulnerability.
Recommendations For VMware Workspace ONE Access versions 20.10 through 21.08, update to a version that contains a fix for this issue. For VMware Identity Manager versions 3.3.3 through 3.3.5, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to the vulnerable component to minimize the risk of exploitation.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02318
CVE-2021-22056

Affected Products

Vmware Identity Manager
Vmware Workspace One Access