VDB

CVE-2022-31657

CVE-2022-31657 PUBLISHED

------------ On August 2, 2022 VMware released a critical security advisory, VMSA-2022-0021, that addresses security vulnerabilities found and resolved in VMware’s Workspace ONE Access, VMware Identity Manager (vIDM), vRealize Lifecycle Manager, vRealize Automation, and VMware Cloud Foundation products. VMware Identity Manager is also an optional external component that can provide authentication and authorization for other products, such as NSX, vRealize Operations, vRealize Log Insight, and vRealize Network Insight. [The VMSA](https://www.vmware.com/security/advisories/VMSA-2022-0021.html) will always be the source of truth for what products & versions are affected, the workarounds, and proper patches to keep your organization secure. This document is a corollary to the advisory and includes self-service information to help you and your organization decide how to respond. These vulnerabilities are authentication bypass, remote code execution, and privilege escalation vulnerabilities. An authentication bypass means that an attacker with network access to Workspace ONE Access, VMware Identity Manager, and vRealize Automation can obtain administrator access. Remote code execution (RCE) means that an attacker can trick the components into executing commands that aren’t authorized. Privilege escalation means that an attacker with local access can become root on the virtual appliance. It is extremely important that you quickly take steps to patch or mitigate these issues in o

EPSS 1.32% · 68.1th percentile

Risk Scores

EPSS Score
1.32%
68.1th percentile

Timeline

  • Aug 2, 2022 CVE Published
  • Aug 6, 2022 EPSS Score
  • Sep 21, 2022 EPSS Score
  • Dec 23, 2022 EPSS Score
  • Feb 7, 2023 EPSS Score
  • Mar 26, 2023 EPSS Score
  • May 11, 2023 EPSS Score
  • Aug 12, 2023 EPSS Score
  • Sep 27, 2023 EPSS Score
  • Dec 29, 2023 EPSS Score
  • Feb 13, 2024 EPSS Score
  • Mar 30, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›