PT-2022-4055 · Vmware · Vmware Identity Manager+2
Mr_Me
·
Published
2022-08-02
·
Updated
2022-08-11
·
CVE-2022-31665
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:S/C:P/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
VMware Workspace ONE Access, Identity Manager and vRealize Automation (affected versions not specified)
Description
The issue is related to incorrect code generation management in the administration platform of VMware Workspace One Access, VMware Identity Manager console, and VMware vRealize Automation virtual infrastructure management tool. A malicious actor with administrator and network access can trigger a remote code execution. This allows an attacker to execute arbitrary code remotely.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Special Elements Injection
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vmware Identity Manager
Vmware Workspace One Access
Vmware Vrealize Automation