PT-2022-2186 · Vmware · Vmware Identity Manager+2
Mr_Me
+1
·
Published
2022-01-10
·
Updated
2023-08-08
·
CVE-2022-22961
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
VMware Workspace ONE Access (affected versions not specified)
VMware Identity Manager (affected versions not specified)
vRealize Automation (affected versions not specified)
Description
The issue is related to an information disclosure vulnerability. It allows a malicious actor with remote access to leak the hostname of the target system. Successful exploitation can lead to targeting victims. The vulnerability is associated with the disclosure of protected information.
Recommendations
For VMware Workspace ONE Access, consider restricting access to sensitive information until a fix is available.
For VMware Identity Manager, restrict access to the administration console to minimize the risk of exploitation.
For vRealize Automation, avoid using the platform for sensitive operations until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vmware Identity Manager
Vmware Workspace One Access
Vrealize Automation