PT-2022-4046 · Vmware · Vmware Identity Manager+1

Tom Tervoort

·

Published

2022-08-02

·

Updated

2023-08-08

·

CVE-2022-31657

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VMware Workspace ONE Access and Identity Manager (affected versions not specified)
Description The issue is related to a URL injection vulnerability. A malicious actor with network access may be able to redirect an authenticated user to an arbitrary domain. This is due to incorrect neutralization of special elements in output.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Special Elements Injection

Weakness Enumeration

Related Identifiers

BDU:2022-04880
CVE-2022-31657

Affected Products

Vmware Identity Manager
Vmware Workspace One Access