PT-2022-4061 · Vmware · Connector+3

Petrusviet

·

Published

2022-08-02

·

Updated

2022-08-11

·

CVE-2022-31662

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions VMware Workspace ONE Access, Identity Manager, Connectors and vRealize Automation (affected versions not specified)
Description The issue is related to a path traversal vulnerability. A malicious actor with network access may be able to access arbitrary files. The vulnerability is caused by incorrect restriction of the directory path name with limited access. Exploitation of the vulnerability may allow a remote attacker to read arbitrary files in the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2022-04895
CVE-2022-31662

Affected Products

Connector
Identity Manager
Vmware Workspace One Access
Vrealize Automation