PT-2022-2141 · Vmware · Vmware Identity Manager+2
Mr_Me
+1
·
Published
2022-04-06
·
Updated
2022-04-21
·
CVE-2022-22959
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VMware Workspace ONE Access (affected versions not specified)
VMware Identity Manager (affected versions not specified)
VMware vRealize Automation (affected versions not specified)
Description
The issue is related to a cross-site request forgery vulnerability. A malicious actor can trick a user into unintentionally validating a malicious JDBC URI through a cross-site request forgery. The vulnerability is associated with insufficient checking of the source of HTTP requests, which can allow a remote attacker to carry out CSRF attacks using a specially crafted web page.
Recommendations
For VMware Workspace ONE Access, consider implementing additional validation for HTTP requests to prevent cross-site request forgery attacks.
For VMware Identity Manager, restrict access to sensitive operations that can be triggered by a malicious JDBC URI until a fix is available.
For VMware vRealize Automation, as a temporary workaround, consider disabling the functionality that allows validation of JDBC URIs through user-initiated requests until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vmware Identity Manager
Vmware Workspace One Access
Vmware Vrealize Automation