PT-2022-6060 · Vmware · Vmware Workspace One Assist

Published

2022-11-08

·

Updated

2022-11-10

·

CVE-2022-31688

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions VMware Workspace ONE Assist versions prior to 22.10
Description The issue arises from improper user input sanitization, allowing a malicious actor with some user interaction to inject javascript code in the target user's window, thus enabling a reflected cross-site scripting (XSS) attack. This could potentially be exploited by a remote attacker to conduct an XSS attack.
Recommendations For versions prior to 22.10, update to version 22.10 or later to resolve the issue. As a temporary workaround, consider restricting user interaction with potentially malicious inputs until a patch is applied.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2022-07524
CVE-2022-31688

Affected Products

Vmware Workspace One Assist