PT-2022-4055 · Vmware · Vmware Identity Manager+2

Mr_Me

·

Published

2022-08-02

·

Updated

2022-08-11

·

CVE-2022-31665

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:P/I:C/A:N
Name of the Vulnerable Software and Affected Versions VMware Workspace ONE Access, Identity Manager and vRealize Automation (affected versions not specified)
Description The issue is related to incorrect code generation management in the administration platform of VMware Workspace One Access, VMware Identity Manager console, and VMware vRealize Automation virtual infrastructure management tool. A malicious actor with administrator and network access can trigger a remote code execution. This allows an attacker to execute arbitrary code remotely.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Special Elements Injection

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2022-04889
CVE-2022-31665

Affected Products

Vmware Identity Manager
Vmware Workspace One Access
Vmware Vrealize Automation