PT-2022-2141 · Vmware · Vmware Identity Manager+2

Mr_Me

+1

·

Published

2022-04-06

·

Updated

2022-04-21

·

CVE-2022-22959

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VMware Workspace ONE Access (affected versions not specified) VMware Identity Manager (affected versions not specified) VMware vRealize Automation (affected versions not specified)
Description The issue is related to a cross-site request forgery vulnerability. A malicious actor can trick a user into unintentionally validating a malicious JDBC URI through a cross-site request forgery. The vulnerability is associated with insufficient checking of the source of HTTP requests, which can allow a remote attacker to carry out CSRF attacks using a specially crafted web page.
Recommendations For VMware Workspace ONE Access, consider implementing additional validation for HTTP requests to prevent cross-site request forgery attacks. For VMware Identity Manager, restrict access to sensitive operations that can be triggered by a malicious JDBC URI until a fix is available. For VMware vRealize Automation, as a temporary workaround, consider disabling the functionality that allows validation of JDBC URIs through user-initiated requests until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02031
CVE-2022-22959

Affected Products

Vmware Identity Manager
Vmware Workspace One Access
Vmware Vrealize Automation