CVE-2022-22972
------------ On May 18, 2022 VMware released a critical security advisory, VMSA-2022-0014, that addresses security vulnerabilities found and resolved in VMware’s Workspace ONE Access, VMware Identity Manager (vIDM), vRealize Lifecycle Manager, vRealize Automation, and VMware Cloud Foundation products. VMware Identity Manager is also an optional external component that can provide authentication and authorization for other products, such as NSX, vRealize Operations, vRealize Log Insight, and vRealize Network Insight. The VMSA will always be the source of truth for what products & versions are affected, the workarounds, and proper patches to keep your organization secure. This document is a corollary to the advisory and includes self-service information to help you and your organization decide how to respond.
EPSS 56.30% · 99.0th percentile
Risk Scores
Timeline
- Jan 20, 1970 VulnCheck XDB Entry
- Jan 20, 1970 VulnCheck XDB Entry
- Aug 12, 2021 VulnCheck KEV Exploitation
- May 18, 2022 CVE Published
- May 19, 2022 PoC Published
- May 21, 2022 EPSS Score
- May 29, 2022 EPSS Score
- May 30, 2022 Nuclei Template
- May 30, 2022 Fix Commit
- Mar 7, 2023 EPSS Score
- Mar 27, 2023 EPSS Score
- Apr 20, 2023 EPSS Score