ZeroHour

CVE-2022-22955

CVSS 3.1
9.8 critical
EPSS
8%p94
Published
()
Modified
Description

VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.

Vendors
vmware
Products
identity manager, vrealize automation, workspace one access
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news