PT-2022-2186 · Vmware · Vmware Identity Manager+2

Mr_Me

+1

·

Published

2022-01-10

·

Updated

2023-08-08

·

CVE-2022-22961

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions VMware Workspace ONE Access (affected versions not specified) VMware Identity Manager (affected versions not specified) vRealize Automation (affected versions not specified)
Description The issue is related to an information disclosure vulnerability. It allows a malicious actor with remote access to leak the hostname of the target system. Successful exploitation can lead to targeting victims. The vulnerability is associated with the disclosure of protected information.
Recommendations For VMware Workspace ONE Access, consider restricting access to sensitive information until a fix is available. For VMware Identity Manager, restrict access to the administration console to minimize the risk of exploitation. For vRealize Automation, avoid using the platform for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2022-02213
CVE-2022-22961

Affected Products

Vmware Identity Manager
Vmware Workspace One Access
Vrealize Automation