VDB

CVE-2022-31656

CVE-2022-31656 PUBLISHED

------------ On August 2, 2022 VMware released a critical security advisory, VMSA-2022-0021, that addresses security vulnerabilities found and resolved in VMware’s Workspace ONE Access, VMware Identity Manager (vIDM), vRealize Lifecycle Manager, vRealize Automation, and VMware Cloud Foundation products. VMware Identity Manager is also an optional external component that can provide authentication and authorization for other products, such as NSX, vRealize Operations, vRealize Log Insight, and vRealize Network Insight. [The VMSA](https://www.vmware.com/security/advisories/VMSA-2022-0021.html) will always be the source of truth for what products & versions are affected, the workarounds, and proper patches to keep your organization secure. This document is a corollary to the advisory and includes self-service information to help you and your organization decide how to respond. These vulnerabilities are authentication bypass, remote code execution, and privilege escalation vulnerabilities. An authentication bypass means that an attacker with network access to Workspace ONE Access, VMware Identity Manager, and vRealize Automation can obtain administrator access. Remote code execution (RCE) means that an attacker can trick the components into executing commands that aren’t authorized. Privilege escalation means that an attacker with local access can become root on the virtual appliance. It is extremely important that you quickly take steps to patch or mitigate these issues in o

EPSS 22.94% · 97.5th percentile

Risk Scores

EPSS Score
22.94%
97.5th percentile

Timeline

  • CVE Published
  • Aug 3, 2022 PoC Published
  • Aug 3, 2022 PoC Published
  • Aug 6, 2022 EPSS Score
  • Aug 10, 2022 PoC Published
  • Mar 7, 2023 EPSS Score
  • Mar 24, 2023 EPSS Score
  • May 9, 2023 EPSS Score
  • Jun 1, 2023 EPSS Score
  • Jun 25, 2023 EPSS Score
  • Aug 1, 2023 EPSS Score
  • Oct 2, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›