PT-2022-2145 · Vmware · Vmware Workspace One Identity Manager+1
Mr_Me
+1
·
Published
2022-04-06
·
Updated
2025-12-05
·
CVE-2022-22954
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VMware Workspace ONE Access and Identity Manager
VMware Cloud Foundation
vRealize Suite Lifecycle Manager
Description
The software contains a remote code execution issue due to a server-side template injection. A malicious actor with network access can trigger this injection, potentially leading to remote code execution. The issue is related to improper handling of code generation within the Template Handler component. Exploitation can be achieved through a crafted HTTP request targeting the
/catalog-portal/ui/oauth/verify API Endpoint with the deviceUdid parameter. The payload utilizes the freemarker.template.utility.Execute function to execute arbitrary commands. Reports indicate that the vulnerability has been actively exploited by the Rocket Kitten APT group to gain initial access and deploy backdoors, including Core Impact. The vulnerability allows for the highest level of privileged access to virtualized host and guest environments.Recommendations
Versions prior to the fix for CVE-2022-22954 should be updated.
As a temporary workaround, consider disabling the vulnerable component Template Handler until a patch is available.
Restrict access to the
/catalog-portal/ui/oauth/verify API Endpoint to minimize the risk of exploitation.Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vmware Workspace One Access
Vmware Workspace One Identity Manager