PT-2021-6847 · Vmware · Vmware Workspace One Access+1
Keiran Sampson
+1
·
Published
2021-12-16
·
Updated
2022-01-19
·
CVE-2021-22056
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
VMware Workspace ONE Access versions 20.10 through 21.08
VMware Identity Manager versions 3.3.3 through 3.3.5
Description
The issue is related to insufficient validation of incoming requests, allowing a remote attacker to impact the confidentiality and integrity of protected information using specially crafted HTTP requests. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response. This is a Server-Side Request Forgery (SSRF) vulnerability.
Recommendations
For VMware Workspace ONE Access versions 20.10 through 21.08, update to a version that contains a fix for this issue.
For VMware Identity Manager versions 3.3.3 through 3.3.5, update to a version that contains a fix for this issue.
As a temporary workaround, consider restricting access to the vulnerable component to minimize the risk of exploitation.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vmware Identity Manager
Vmware Workspace One Access