ZeroHour

CVE-2022-22956

CVSS 3.1
9.8 critical
EPSS
50%p99
Published
()
Modified
Description

VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.

Vendors
vmware
Products
identity manager, vrealize automation, workspace one access
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news